6.7

CVE-2021-4178

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Fabric8-kubernetes Version >= 5.0.1 < 5.0.3
Redhat ≫ Fabric8-kubernetes Version >= 5.1.0 < 5.1.2
Redhat ≫ Fabric8-kubernetes Version >= 5.2.0 < 5.3.2
Redhat ≫ Fabric8-kubernetes Version >= 5.5.0 < 5.7.4
Redhat ≫ Fabric8-kubernetes Version >= 5.9.0 < 5.10.2
Redhat ≫ Fabric8-kubernetes Version >= 5.11.0 < 5.11.2
Redhat ≫ Fabric8-kubernetes Version 5.0.0 Update beta1
Redhat ≫ Fabric8-kubernetes Version 5.8.0
Redhat ≫ A-mq Streams Version 2.0.1
Redhat ≫ Build Of Quarkus Version 2.2.5
Redhat ≫ Descision Manager Version 7.0
Redhat ≫ Fuse Version 7.11
Redhat ≫ Integration Camel K Version -
Redhat ≫ Integration Camel Quarkus Version 2.2.1
Redhat ≫ Process Automation Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://access.redhat.com/security/cve/CVE-2021-4178
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2034388
Vendor Advisory
Issue Tracking
https://github.com/advisories/GHSA-98g7-rxmf-rrxm
Third Party Advisory
https://github.com/fabric8io/kubernetes-client/issues/3653
Third Party Advisory
Issue Tracking