Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20218

Опубликовано: 12 янв. 2021
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client copy command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client copy command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability.

Отчет

In OpenShift Container Platform 4 (OCP) there are no plans to maintain the ose-logging-elasticsearch5 container, therefore it has been marked wontfix at this time and maybe fixed in a future update. Red Hat CodeReady WorkSpaces 2.7.0 does not ship fabric8-kubernetes-client and is therefore not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12kubernetes-clientAffected
Red Hat JBoss Fuse 6kubernetes-clientNot affected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Will not fix
Red Hat AMQ Online 1.7.0 GAkubernetes-clientFixedRHSA-2021:098625.03.2021
Red Hat Fuse 7.10kubernetes-clientFixedRHSA-2021:513414.12.2021
Red Hat Integrationkubernetes-clientFixedRHSA-2021:320518.08.2021
Red Hat Integration Camel Quarkus 2kubernetes-clientFixedRHSA-2021:320718.08.2021
Red Hat OpenShift Container Platform 4.7jenkins-2-pluginsFixedRHSA-2021:100605.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1923405fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise

EPSS

Процентиль: 69%
0.00594
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
почти 5 лет назад

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2

CVSS3: 7.4
github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client

EPSS

Процентиль: 69%
0.00594
Низкий

7.4 High

CVSS3