Impact
The vulnerability is a path traversal flaw in the DecompressTarGz function of keadm that concatenates archive entry names without proper validation on Windows edge nodes. This flaw permits an attacker who controls or influences the archive being extracted to write or overwrite files outside the intended extraction directory, such as configuration, executable, or service files. The resulting arbitrary file write can lead to persistent system modification or code execution, taking advantage of the permissions held by the keadm process.
Affected Systems
KubeEdge version 1.16.0 through 1.21.2, 1.22.2, and 1.23.1 on Windows edge nodes are vulnerable. The issue exists in the keadm component during node join or installation. Versions 1.21.2, 1.22.2, and 1.23.1, among others, contain the fix.
Risk and Exploitability
The flaw receives a CVSS score of 8.1, indicating a high severity. EPSS is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, occurring when an attacker supplies a malicious archive used by keadm during the join or install process, potentially by compromising the download source or by malware on the edge node. Successful exploitation would allow the attacker to write arbitrary files with keadm’s privileges, potentially enabling persistent code execution or system compromise.
OpenCVE Enrichment