Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-25743

Опубликовано: 06 янв. 2022
Источник: redhat
CVSS3: 3

Описание

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/agent-service-rhel8Fix deferred
Red Hat Ansible Automation Platform 1.2kubernetesAffected
Red Hat Ansible Tower 3kubernetesAffected
Red Hat OpenShift Container Platform 3.11atomic-openshiftFix deferred
Red Hat OpenShift Container Platform 4openshiftFix deferred
Red Hat OpenShift Container Platform 4openshift-clientsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2042418kubernetes: kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal

3 Low

CVSS3

Связанные уязвимости

CVSS3: 3
ubuntu
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
nvd
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
debian
больше 3 лет назад

kubectl does not neutralize escape, meta or control sequences containe ...

suse-cvrf
10 месяцев назад

Security update for kubernetes1.25

suse-cvrf
10 месяцев назад

Security update for kubernetes1.24

3 Low

CVSS3