CVE-2021-20218
published 2021-03-16CVE-2021-20218: A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the…
PriorityP343high7.4CVSS 3.1
AVNACHPRNUINSUCNIHAH
EPSS
1.31%
67.5th percentile
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | codeready_studio | — | — |
| redhat | descision_manager | — | — |
| redhat | jboss_fuse | — | — |
| redhat | kubernetes-client | >= 4.12.0 < 4.13.2 | 4.13.2 |
| redhat | kubernetes-client | >= 4.2.0 < 4.7.2 | 4.7.2 |
| redhat | kubernetes-client | >= 4.8.0 < 4.11.2 | 4.11.2 |
| redhat | kubernetes-client | >= 5.0.0 < 5.0.2 | 5.0.2 |
| redhat | openshift_container_platform | — | — |
| redhat | process_automation | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
ghsa·2022-05-24
CVE-2021-20218 [HIGH] CWE-22 Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
OSV
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
osv·2022-05-24
CVE-2021-20218 [HIGH] Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
Red Hat
fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise
vendor_redhat·2021-01-12·CVSS 7.4
CVE-2021-20218 [HIGH] CWE-22 fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise
fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest
No detection rules found.
No public exploits indexed.
2021-03-16
Published