GHSA-jwh2-ffg4-48xc
HIGHCVE-2021-20218A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client copy command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernete
- Affected
- >= 4.12.0, <= 4.13.1, >= 4.2.0, <= 4.7.1, >= 4.8.0, <= 4.11.1
- Fixed in
- 4.13.2
- Weakness
- CWE-22
- Published
- 2022-05-24
- Source
- github