CVE-2021-20218: Path Traversal
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client copy command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability.
Other sources
A flaw was found in the fabric8 kubernetes-client where a malicious pod/container may cause applications using the fabric8 kubernetes-client copy command to extract files outside the working path, the main impact of this flaw is to integrity and availability of the kubernetes-client host.
Upstream report: https://github.com/fabric8io/kubernetes-client/issues/2715
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-20218?
CVE-2021-20218 is a vulnerability in the fabric8 kubernetes-client that allows a malicious pod/container to extract files outside the working path.
What is the impact of CVE-2021-20218?
The highest threat from CVE-2021-20218 is to integrity.
How can a malicious pod/container exploit CVE-2021-20218?
A malicious pod/container can exploit CVE-2021-20218 by using the fabric8 kubernetes-client 'copy' command to extract files outside the working path.
Which versions of fabric8 kubernetes-client are affected by CVE-2021-20218?
Versions 4.2.0 and after of the fabric8 kubernetes-client are affected by CVE-2021-20218.
Where can I find more information about CVE-2021-20218?
You can find more information about CVE-2021-20218 on the GitHub issue page and the Red Hat security advisory.