Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 4.2.0, <= 4.7.1
>= 4.8.0, <= 4.11.1
>= 4.12.0, <= 4.13.1
>= 5.0.0, <= 5.0.1
Patched versions
4.7.2
4.11.2
4.13.2
5.0.2
Description
Published by the National Vulnerability Database
Mar 16, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 22, 2022
Last updated
Jan 27, 2023
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client
copy
command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2References