#VU85950 Path traversal in Java client for Kubernetes & OpenShift - CVE-2021-20218
Published: January 31, 2024
Java client for Kubernetes & OpenShift
fabric8io
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to malicious pod/container can cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.