漏洞信息详情
Rohan Kumar kubernetes-client 路径遍历漏洞
漏洞简介
Rohan Kumar kubernetes-client是 (Rohan Kumar)开源的一个应用软件。提供流畅的DSL访问完整的Kubernetes和 OpenShift REST API。
fabric8 kubernetes-client in version 4.2.0 and after 存在安全漏洞,该漏洞源于 copy 命令提可取工作路径之外的文件。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/fabric8io/kubernetes-client/issues/2715
参考网址
来源:MISC
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1923405
来源:MISC
链接:https://github.com/fabric8io/kubernetes-client/issues/2715
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162337/Red-Hat-Security-Advisory-2021-1369-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163872/Red-Hat-Security-Advisory-2021-3205-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162012/Red-Hat-Security-Advisory-2021-1004-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1080
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-20218
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2816
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1406
受影响实体
暂无
补丁
- Rohan Kumar kubernetes-client 路径遍历漏洞的修复措施<!--2021-3-16-->
还没有评论,来说两句吧...