A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client copy command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "12.0"
}
],
"vendor_product": "redhat:codeready_studio",
"cpes": [
"cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "7.0"
}
],
"vendor_product": "redhat:descision_manager",
"cpes": [
"cpe:2.3:a:redhat:descision_manager:7.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "7.0.0"
}
],
"vendor_product": "redhat:jboss_fuse",
"cpes": [
"cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "3.11"
}
],
"vendor_product": "redhat:openshift_container_platform",
"cpes": [
"cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "7.0"
}
],
"vendor_product": "redhat:process_automation",
"cpes": [
"cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}{
"extracted_events": [
{
"introduced": "4.2.0"
},
{
"fixed": "4.7.2"
},
{
"introduced": "4.8.0"
},
{
"fixed": "4.11.2"
},
{
"introduced": "4.12.0"
},
{
"fixed": "4.13.2"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.2"
}
],
"cpe": "cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}