Kubernetes Java client libraries unvalidated path traversal in Copy implementation
Published Jan 21, 2021
9.1
CRITICALCVSS 3.1
EPSS 3.64%
Description
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.0.1
- Version 9.0StatusaffectedConstraints<9.0.2
- Version all versions prior to 9.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes Java Client | n/a |
|
- < 9.0.2
- ≥ 10.0.0 · < 10.0.1
No data.
Red Hat Decision Manager 7
kubernetes-client
Not affected
Red Hat Fuse 7
kubernetes-client
Not affected
Red Hat Integration Camel K 1
kubernetes-client
Not affected
Red Hat JBoss Fuse 6
kubernetes-client
Not affected
Red Hat Process Automation 7
kubernetes-client
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Decision Manager 7 | kubernetes-client | Not affected | n/a |
| Red Hat Fuse 7 | kubernetes-client | Not affected | n/a |
| Red Hat Integration Camel K 1 | kubernetes-client | Not affected | n/a |
| Red Hat JBoss Fuse 6 | kubernetes-client | Not affected | n/a |
| Red Hat Process Automation 7 | kubernetes-client | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to 9.0.2, 10.0.1 or 11.0.0 versions of the library.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
2 other sources (GHSA, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.64% (0.03643) | 89.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.55% (0.03545) | 87.75th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.36% (0.00355) | 72.30th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.36% (0.00355) | 71.25th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.36% (0.00355) | 68.88th | v3 (v2023.03.01) |
| Oct 7, 2023 | 0.49% (0.00493) | 73.39th | v3 (v2023.03.01) |
| Aug 28, 2023 | 0.43% (0.00433) | 71.36th | v3 (v2023.03.01) |
| Aug 2, 2023 | 0.42% (0.00420) | 70.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.30% (0.00296) | 64.46th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.11% (0.01108) | 54.89th | v2 (v2022.01.01) |
| Dec 30, 2022 | 8.93% (0.08934) | 93.68th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 8.93% (0.08934) | 82.99th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.21% (0.06208) | 81.93th | v1 |
| Jan 6, 2022 | 6.21% (0.06208) | 81.75th | v1 |
| Sep 1, 2021 | 1.45% (0.01454) | 71.88th | v1 |
| Apr 14, 2021 | 1.45% (0.01454) | 0.00th | v1 |
References (17)
- https://access.redhat.com/security/cve/CVE-2020-8570 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1915464 Issue Tracking
- https://github.com/advisories/GHSA-cghx-9gcr-r42x Advisory
- https://github.com/kubernetes-client/java/commit/858316ae8bc1145005a0310e1f65f95d2389a589
- https://github.com/kubernetes-client/java/issues/1491 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/kubernetes-client/java/pull/1450
- https://groups.google.com/g/kubernetes-security-announce/c/sd5h73sFPrg x_refsource_MISCMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6@%3Ccommits.druid.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-8570
- https://www.cve.org/CVERecord?id=CVE-2020-8570
Change history (0)
No recorded changes yet.