PT-2021-12794 · Unknown · Kubernetes Java Client Libraries

Published

2021-01-21

·

Updated

2022-10-07

·

CVE-2020-8570

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Kubernetes Java client libraries versions prior to 9.0.1 Kubernetes Java client libraries version 10.0.0
Description: The issue allows writes to paths outside of the current directory when copying multiple files from a remote pod that sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
Recommendations: For versions prior to 9.0.1, update to version 9.0.1 or later to resolve the issue. For version 10.0.0, update to a version later than 10.0.0 to resolve the issue. As a temporary workaround, consider restricting the use of the archive copying functionality from remote pods until a patch is available.

Fix

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-8570
GHSA-CGHX-9GCR-R42X

Affected Products

Kubernetes Java Client Libraries