CVE-2020-8570: Kubernetes Java client libraries unvalidated path traversal in Copy implementation
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-8570.
What is the severity rating of CVE-2020-8570?
CVE-2020-8570 has a severity rating of 9.1 (Critical).
What is the affected software?
The affected software is Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.2.
What is the impact of this vulnerability?
This vulnerability allows writes to paths outside of the current directory and can potentially overwrite any files on the system.
Are there any references for further information?
Yes, you can find more information about CVE-2020-8570 at the following references: [link1](https://github.com/kubernetes-client/java/issues/1491), [link2](https://groups.google.com/g/kubernetes-security-announce/c/sd5h73sFPrg), [link3](https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40@%3Ccommits.druid.apache.org%3E)