CVE-2021-4178: Code Injection
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Other sources
A flaw was found in kubernetes-client. An insecure deserialization issue due to the use of the SnakeYAML library may lead to arbitrary code execution.
References:
https://github.com/fabric8io/kubernetes-client/issues/3653
— Red Hat
fabric8 Kubernetes client had an arbitrary code execution flaw in versions 5.0.0-beta-1 and higher. Attackers could potentially insert malicious YAMLs due to misconfigured YAML parsing.
— GitHub
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-4178?
CVE-2021-4178 is an arbitrary code execution flaw in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above.
How does CVE-2021-4178 affect the Fabric 8 Kubernetes client?
CVE-2021-4178 allows a local and privileged attacker to supply malicious YAML due to an improperly configured YAML parsing.
What is the severity of CVE-2021-4178?
The severity of CVE-2021-4178 is medium with a CVSS score of 6.7.
How can I fix CVE-2021-4178 in the Fabric 8 Kubernetes client?
To fix CVE-2021-4178, update the Fabric 8 Kubernetes client to version 5.0.3 or higher.
Where can I find more information about CVE-2021-4178?
More information about CVE-2021-4178 can be found in the following references: [link_1], [link_2], [link_3].