Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0501 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. |
Github GHSA |
GHSA-cghx-9gcr-r42x | Path Traversal in the Java Kubernetes Client |
Fixes
Solution
Upgrade to 9.0.2, 10.0.1 or 11.0.0 versions of the library.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T22:01:55.884Z
Reserved: 2020-02-03T00:00:00
Link: CVE-2020-8570
No data.
Status : Modified
Published: 2021-01-21T17:15:14.327
Modified: 2024-11-21T05:39:03.143
Link: CVE-2020-8570
OpenCVE Enrichment
No data.
EUVD
Github GHSA