Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9jg-8p32-2f55

Опубликовано: 08 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3

Описание

kubectl ANSI escape characters not filtered

kubectl (k8s.io/kubernetes/pkg/kubectl) does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.26.0-alpha.3

1.26.0-alpha.3

EPSS

Процентиль: 57%
0.00353
Низкий

3 Low

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 3
ubuntu
почти 4 года назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
redhat
почти 4 года назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
nvd
почти 4 года назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
debian
почти 4 года назад

kubectl does not neutralize escape, meta or control sequences containe ...

suse-cvrf
около 1 года назад

Security update for kubernetes1.25

EPSS

Процентиль: 57%
0.00353
Низкий

3 Low

CVSS3

Дефекты

CWE-150