PT-2021-12794 · Unknown · Kubernetes Java Client Libraries
Published
2021-01-21
·
Updated
2022-10-07
·
CVE-2020-8570
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Kubernetes Java client libraries versions prior to 9.0.1
Kubernetes Java client libraries version 10.0.0
Description:
The issue allows writes to paths outside of the current directory when copying multiple files from a remote pod that sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
Recommendations:
For versions prior to 9.0.1, update to version 9.0.1 or later to resolve the issue.
For version 10.0.0, update to a version later than 10.0.0 to resolve the issue.
As a temporary workaround, consider restricting the use of the archive copying functionality from remote pods until a patch is available.
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kubernetes Java Client Libraries