maven package report

Is k8s.io/kubernetes safe?

5 known vulnerabilities, worst severity HIGH.

cvss
7.1

how bad it is if exploited, out of 10

epss
1.1%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-mm7g-f2gg-cw8g, the advisory selected below

// advisories

GHSA-mm7g-f2gg-cw8g

HIGHCVE-2017-1002102

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Affected
>=1.3.0, <1.7.14, >=1.8.0, <1.8.9, >=1.9.0, <1.9.4
Fixed in
1.7.14
Published
2022-05-13
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:48 UTC. The most recent advisory here was published 2024-04-23. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is k8s.io/kubernetes safe? maven package security report | CyberXYZ