Skip to content

fabric8 kubernetes-client vulnerable

Moderate severity GitHub Reviewed Published Jul 15, 2022 to the GitHub Advisory Database • Updated Jan 31, 2023

Package

maven io.fabric8:kubernetes-client (Maven)

Affected versions

>= 5.0.0-beta-1, < 5.0.3
>= 5.1.0, < 5.1.2
>= 5.2.0, < 5.3.2
>= 5.5.0, < 5.7.4
>= 5.8.0, < 5.8.1
>= 5.9.0, < 5.10.2
>= 5.11.0, < 5.11.2

Patched versions

5.0.3
5.1.2
5.3.2
5.7.4
5.8.1
5.10.2
5.11.2

Description

fabric8 Kubernetes client had an arbitrary code execution flaw in versions 5.0.0-beta-1 and higher. Attackers could potentially insert malicious YAMLs due to misconfigured YAML parsing.

References

Published to the GitHub Advisory Database Jul 15, 2022
Reviewed Jul 15, 2022
Published by the National Vulnerability Database Aug 24, 2022
Last updated Jan 31, 2023

Severity

Moderate
6.7
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE ID

CVE-2021-4178

GHSA ID

GHSA-98g7-rxmf-rrxm

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.