Path traversal in Java client for Kubernetes & OpenShift - CVE-2021-20218
Published: January 31, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to malicious pod/container can cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
IBM Cloud Pak for Watson AIOps
Fuse
IBM Observability with Instana
How to mitigate CVE-2021-20218
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Fuse - update to 7.10.0
IBM Observability with Instana - update to 265