Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9jg-8p32-2f55

Опубликовано: 08 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3

Описание

kubectl ANSI escape characters not filtered

kubectl (k8s.io/kubernetes/pkg/kubectl) does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.26.0-alpha.3

1.26.0-alpha.3

EPSS

Процентиль: 53%
0.00303
Низкий

3 Low

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 3
ubuntu
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
redhat
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
nvd
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
debian
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences containe ...

suse-cvrf
10 месяцев назад

Security update for kubernetes1.25

EPSS

Процентиль: 53%
0.00303
Низкий

3 Low

CVSS3

Дефекты

CWE-150