{"id":"CVE-2021-20218","details":"A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2","aliases":["GHSA-jwh2-ffg4-48xc"],"modified":"2026-07-07T08:50:22.536455455Z","published":"2021-03-16T21:15:10.930Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.0"},{"last_affected":"12.0"}],"source":"CPE_STRING","vendor_product":"redhat:codeready_studio"},{"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:descision_manager","cpes":["cpe:2.3:a:redhat:descision_manager:7.0:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_fuse"},{"vendor_product":"redhat:openshift_container_platform","cpes":["cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.11"},{"last_affected":"3.11"}],"source":"CPE_STRING"},{"vendor_product":"redhat:process_automation","cpes":["cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING"}]},"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1923405"},{"type":"FIX","url":"https://github.com/fabric8io/kubernetes-client/issues/2715"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fabric8io/kubernetes-client","events":[{"introduced":"6a4ed988a3c7f013e5173cf69252a7272471535d"},{"fixed":"c9d712ecfa82d3537912bff5d108aa601e7f0109"},{"introduced":"53f70355d6b140ae4d25f0fe8704aee064fda5d7"},{"fixed":"fee2cb0813d2322f7476fb481ee745d54ad5d5ba"},{"introduced":"9dc84ecafba374b23324cff60bee56c53737315a"},{"fixed":"36e898e4ad08b1539535e55c3878c8a3602ffdbc"},{"introduced":"427919c5ae79ea7982f3a9d0a484e37e3ed0816b"},{"fixed":"1d1b3d404836871c4d0fc0a35dafe5d40369b519"}],"database_specific":{"cpe":"cpe:2.3:a:redhat:kubernetes-client:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.2.0"},{"fixed":"4.7.2"},{"introduced":"4.8.0"},{"fixed":"4.11.2"},{"introduced":"4.12.0"},{"fixed":"4.13.2"},{"introduced":"5.0.0"},{"fixed":"5.0.2"}],"source":"CPE_RANGE"}}],"versions":["v4.11.1","v5.0.1","v4.13.1","v4.13.0","v5.0.0","v4.12.0","v4.11.0","v4.10.2","v4.9.1","v4.10.1","v4.10.0","v4.9.0","v4.8.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-20218.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}