Back

CRITICAL

Kubernetes Java client libraries unvalidated path traversal in Copy implementation

Published Jan 21, 2021

Description

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

Affected products

Remediation

Vendor solution

Upgrade to 9.0.2, 10.0.1 or 11.0.0 versions of the library.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Jan 21, 2021
Updated Sep 16, 2024
Reserved Feb 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 12, 2021
GHSA-CGHX-9GCR-R42X