cbcvebase.
CVE-2021-4178
published 2022-08-24

CVE-2021-4178: A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML…

PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.31%
22.9th percentile
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

Affected

14 ranges
VendorProductVersion rangeFixed in
redhata-mq_streams
redhatbuild_of_quarkus
redhatdescision_manager
redhatfabric8-kubernetes
redhatfabric8-kubernetes
redhatfabric8-kubernetes>= 5.0.1 < 5.0.35.0.3
redhatfabric8-kubernetes>= 5.1.0 < 5.1.25.1.2
redhatfabric8-kubernetes>= 5.11.0 < 5.11.25.11.2
redhatfabric8-kubernetes>= 5.2.0 < 5.3.25.3.2
redhatfabric8-kubernetes>= 5.5.0 < 5.7.45.7.4
redhatfabric8-kubernetes>= 5.9.0 < 5.10.25.10.2
redhatfuse
redhatintegration_camel_quarkus
redhatprocess_automation

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.