CVE-2021-20218
Summary
| CVE | CVE-2021-20218 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-16 21:15:00 UTC |
| Updated | 2021-03-25 18:43:00 UTC |
| Description | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1923405 – (CVE-2021-20218) CVE-2021-20218 fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise |
MISC |
bugzilla.redhat.com |
|
| Potential CVE? · Issue #2715 · fabric8io/kubernetes-client · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 770055 Red Hat OpenShift Container Platform 4.7.5 Security and Bug Fix Update (RHSA-2021:1006)
- 770109 Red Hat OpenShift Container Platform 4.7 Security Update (RHSA-2021-1006)