CVE-2021-20218
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
16/03/2021
Last modified:
25/03/2021
Description
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | 4.2.0 (including) | 4.7.2 (excluding) |
| cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | 4.8.0 (including) | 4.11.2 (excluding) |
| cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | 4.12.0 (including) | 4.13.2 (excluding) |
| cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.0.2 (excluding) |
| cpe:2.3:a:redhat:a-mq_online:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:descision_manager:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



