CVE-2021-25743
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/01/2022
Last modified:
13/01/2026
Description
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
Impact
Base Score 3.x
3.00
Severity 3.x
LOW
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | 1.25.0 (including) | |
| cpe:2.3:a:kubernetes:kubernetes:1.26.0:alpha0:*:*:*:*:*:* | ||
| cpe:2.3:a:kubernetes:kubernetes:1.26.0:alpha1:*:*:*:*:*:* | ||
| cpe:2.3:a:kubernetes:kubernetes:1.26.0:alpha2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



