Showing 2 vulnerabilities on this page for Kubernetes Java Client

Signals CISA KEV Ransomware Nuclei
Kubernetes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Code exec via yaml parsing

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

CWE-20CWE-502Oct 11, 2021
CVSS6.7v3.1EPSS0.473%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Kubernetes Java client libraries unvalidated path traversal in Copy implementation

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

CWE-22CWE-23Jan 21, 2021
CVSS9.1v3.1EPSS3.64%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX