CVE-2021-25738

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
11/10/2021
Last modified:
28/10/2022

Description

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:java:*:*:*:*:*:*:*:* 9.0.2 (including)
cpe:2.3:a:kubernetes:java:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.1 (including)
cpe:2.3:a:kubernetes:java:*:*:*:*:*:*:*:* 11.0.0 (including) 11.0.1 (excluding)