kubernetes-client: Insecure deserialization in unmarshalYaml method
Published Aug 24, 2022
6.7
MEDIUMCVSS 3.1
EPSS 0.33%
Description
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Affected products
- Vendor n/a Product Kubernetes-Client Defaultn/a
- Version Affects 5.x versions, Fixed in kubernetes-client v5.0.3 and above.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kubernetes-Client | n/a |
|
Configuration 1
- ≥ 5.0.1 · < 5.0.3
- ≥ 5.1.0 · < 5.1.2
- ≥ 5.2.0 · < 5.3.2
- ≥ 5.5.0 · < 5.7.4
- ≥ 5.9.0 · < 5.10.2
- ≥ 5.11.0 · < 5.11.2
- 5.0.0
- 5.8.0
Configuration 2
- 2.0.1
- 2.2.5
- 7.0
- 7.11
- n/a
- 2.2.1
- n/a
- 7.0
No data.
OCP-Tools-4.13-RHEL-8
jenkins-2-plugins-0:4.13.1684911916-1.el8
Fixed · RHSA-2023:3299
RHINT Camel-Q 2.2.1
n/a
Fixed · RHSA-2022:1013
Red Hat AMQ Streams 1.6.7
n/a
Fixed · RHSA-2022:0467
Red Hat AMQ Streams 2.0.1
kubernetes-client
Fixed · RHSA-2022:0469
Red Hat Fuse 7.11
kubernetes-client
Fixed · RHSA-2022:5532
Red Hat build of Quarkus 2.2.5
kubernetes-client
Fixed · RHSA-2022:0589
Text-Only RHOAR
kubernetes-client
Fixed · RHSA-2022:8761
Red Hat Decision Manager 7
kubernetes-client
Affected
Red Hat Integration Camel K 1
kubernetes-client
Affected
Red Hat Integration Camel Quarkus 1
kubernetes-client
Affected
Red Hat JBoss Fuse 6
kubernetes-client
Not affected
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Affected
Red Hat Process Automation 7
kubernetes-client
Affected
Red Hat build of Quarkus
kubernetes-client
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OCP-Tools-4.13-RHEL-8 | jenkins-2-plugins-0:4.13.1684911916-1.el8 | Fixed | RHSA-2023:3299 |
| RHINT Camel-Q 2.2.1 | n/a | Fixed | RHSA-2022:1013 |
| Red Hat AMQ Streams 1.6.7 | n/a | Fixed | RHSA-2022:0467 |
| Red Hat AMQ Streams 2.0.1 | kubernetes-client | Fixed | RHSA-2022:0469 |
| Red Hat Fuse 7.11 | kubernetes-client | Fixed | RHSA-2022:5532 |
| Red Hat build of Quarkus 2.2.5 | kubernetes-client | Fixed | RHSA-2022:0589 |
| Text-Only RHOAR | kubernetes-client | Fixed | RHSA-2022:8761 |
| Red Hat Decision Manager 7 | kubernetes-client | Affected | n/a |
| Red Hat Integration Camel K 1 | kubernetes-client | Affected | n/a |
| Red Hat Integration Camel Quarkus 1 | kubernetes-client | Affected | n/a |
| Red Hat JBoss Fuse 6 | kubernetes-client | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Affected | n/a |
| Red Hat Process Automation 7 | kubernetes-client | Affected | n/a |
| Red Hat build of Quarkus | kubernetes-client | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat CodeReady Studio 12 is not affected by this flaw because it does not ship a vulnerable version of kubernetes-client; the version that it ships does not use SnakeYAML.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.33% (0.00332) | 23.97th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.31% (0.00309) | 22.31th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00080) | 21.27th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00046) | 19.08th | v3 (v2023.03.01) |
| May 7, 2024 | 0.05% (0.00046) | 16.08th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.36% (0.01365) | 71.56th | v2 (v2022.01.01) |
| Aug 30, 2022 | 1.36% (0.01365) | 70.68th | v2 (v2022.01.01) |
| Aug 25, 2022 | 1.55% (0.01549) | 74.02th | v2 (v2022.01.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2021-4178 x_refsource_MISCVendor Advisory
- https://access.redhat.com/security/cve/cve-2021-4178
- https://bugzilla.redhat.com/show_bug.cgi?id=2034388 x_refsource_MISCIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-98g7-rxmf-rrxm Advisoryx_refsource_MISCThird Party Advisory
- https://github.com/fabric8io/kubernetes-client/commit/445103004d1ed3153d5abb272473451d05891e39
- https://github.com/fabric8io/kubernetes-client/issues/3653 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-4178
- https://www.cve.org/CVERecord?id=CVE-2021-4178
- https://www.mend.io/vulnerability-database/CVE-2021-4178
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-4178 | x_refsource_MISCVendor Advisory | |
| https://access.redhat.com/security/cve/cve-2021-4178 | ||
| https://bugzilla.redhat.com/show_bug.cgi?id=2034388 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-98g7-rxmf-rrxm | Advisoryx_refsource_MISCThird Party Advisory | |
| https://github.com/fabric8io/kubernetes-client/commit/445103004d1ed3153d5abb272473451d05891e39 | ||
| https://github.com/fabric8io/kubernetes-client/issues/3653 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-4178 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-4178 | ||
| https://www.mend.io/vulnerability-database/CVE-2021-4178 |
Change history (0)
No recorded changes yet.