Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8570

Опубликовано: 12 янв. 2021
Источник: redhat
CVSS3: 7.4

Описание

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12kubernetes-clientNot affected
Red Hat Decision Manager 7kubernetes-clientNot affected
Red Hat Fuse 7kubernetes-clientNot affected
Red Hat Integration Camel K 1kubernetes-clientNot affected
Red Hat JBoss Fuse 6kubernetes-clientNot affected
Red Hat Process Automation 7kubernetes-clientNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1915464kubernetes-client: Path Traversal bug in the Java kubernetes client

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 5 лет назад

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

CVSS3: 7.5
github
около 5 лет назад

Path Traversal in the Java Kubernetes Client

7.4 High

CVSS3