CVE-2021-4178
published 2022-08-24CVE-2021-4178: A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML…
PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.31%
22.9th percentile
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | a-mq_streams | — | — |
| redhat | build_of_quarkus | — | — |
| redhat | descision_manager | — | — |
| redhat | fabric8-kubernetes | — | — |
| redhat | fabric8-kubernetes | — | — |
| redhat | fabric8-kubernetes | >= 5.0.1 < 5.0.3 | 5.0.3 |
| redhat | fabric8-kubernetes | >= 5.1.0 < 5.1.2 | 5.1.2 |
| redhat | fabric8-kubernetes | >= 5.11.0 < 5.11.2 | 5.11.2 |
| redhat | fabric8-kubernetes | >= 5.2.0 < 5.3.2 | 5.3.2 |
| redhat | fabric8-kubernetes | >= 5.5.0 < 5.7.4 | 5.7.4 |
| redhat | fabric8-kubernetes | >= 5.9.0 < 5.10.2 | 5.10.2 |
| redhat | fuse | — | — |
| redhat | integration_camel_quarkus | — | — |
| redhat | process_automation | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
fabric8 kubernetes-client vulnerable
ghsa·2022-07-15
CVE-2021-4178 [MEDIUM] CWE-502 fabric8 kubernetes-client vulnerable
fabric8 kubernetes-client vulnerable
fabric8 Kubernetes client had an arbitrary code execution flaw in versions 5.0.0-beta-1 and higher. Attackers could potentially insert malicious YAMLs due to misconfigured YAML parsing.
OSV
fabric8 kubernetes-client vulnerable
osv·2022-07-15
CVE-2021-4178 [MEDIUM] fabric8 kubernetes-client vulnerable
fabric8 kubernetes-client vulnerable
fabric8 Kubernetes client had an arbitrary code execution flaw in versions 5.0.0-beta-1 and higher. Attackers could potentially insert malicious YAMLs due to misconfigured YAML parsing.
Red Hat
kubernetes-client: Insecure deserialization in unmarshalYaml method
vendor_redhat·2022-01-05·CVSS 6.7
CVE-2021-4178 [MEDIUM] CWE-502 kubernetes-client: Insecure deserialization in unmarshalYaml method
kubernetes-client: Insecure deserialization in unmarshalYaml method
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Statement: Red Hat CodeReady Studio 12 is not affected by this flaw because it does not ship a vulnerable version of kubernetes-client; the version that it ships does not use SnakeYAML.
Package: kubernetes-client (Red Hat build of Quarkus) - Affected
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2021-4178https://bugzilla.redhat.com/show_bug.cgi?id=2034388https://github.com/advisories/GHSA-98g7-rxmf-rrxmhttps://github.com/fabric8io/kubernetes-client/issues/3653https://access.redhat.com/security/cve/CVE-2021-4178https://bugzilla.redhat.com/show_bug.cgi?id=2034388https://github.com/advisories/GHSA-98g7-rxmf-rrxmhttps://github.com/fabric8io/kubernetes-client/issues/3653
2022-08-24
Published