Back

MEDIUM

kubernetes-client: Insecure deserialization in unmarshalYaml method

Published Aug 24, 2022

Description

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

Affected products

Remediation

Red Hat statement

Red Hat CodeReady Studio 12 is not affected by this flaw because it does not ship a vulnerable version of kubernetes-client; the version that it ships does not use SnakeYAML.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 24, 2022
Updated Aug 3, 2024
Reserved Dec 27, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 5, 2022
GHSA-98G7-RXMF-RRXM