3
CVE-2021-25743
- EPSS 0.78%
- Veröffentlicht 07.01.2022 00:15:07
- Zuletzt bearbeitet 13.01.2026 02:39:08
- Erkennungen
ANSI escape characters in kubectl output are not being filtered
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kubernetes ≫ Kubernetes Version <= 1.25.0
Kubernetes ≫ Kubernetes Version 1.26.0 Update alpha0
Kubernetes ≫ Kubernetes Version 1.26.0 Update alpha1
Kubernetes ≫ Kubernetes Version 1.26.0 Update alpha2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.51 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3 | 1.3 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:N/I:P/A:N
|
| jordan@liggitt.net | 3 | 1.3 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
|
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
https://github.com/kubernetes/kubernetes/issues/101695
https://security.netapp.com/advisory/ntap-20220217-0003/