CVE-2021-20218 is a path traversal vulnerability in the fabric8 kubernetes-client (versions 4.2.0 and later) that allows a malicious pod/container to extract files outside the intended working directory when the 'copy' command is used. This flaw primarily impacts the integrity and availability of affected systems, including various Red Hat products like OpenShift Container Platform and JBoss Fuse. Rated with a CVSS score of 7.4 (HIGH), it has a network attack vector and low attack complexity, posing a significant risk if exploited. While there is no evidence of active exploitation, public exploit code, or significant community discussion, organizations using affected versions should prioritize patching to mitigate potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.0, < 4.7.2CPE matchmatch criteria | cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | ||
>= 4.8.0, < 4.11.2CPE matchmatch criteria | cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | ||
>= 4.12.0, < 4.13.2CPE matchmatch criteria | cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.2CPE matchmatch criteria | cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:a-mq_online:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.