{"id":"GHSA-98g7-rxmf-rrxm","summary":"fabric8 kubernetes-client vulnerable ","details":"fabric8 Kubernetes client had an arbitrary code execution flaw in versions 5.0.0-beta-1 and higher. Attackers could potentially insert malicious YAMLs due to misconfigured YAML parsing.","aliases":["CVE-2021-4178"],"modified":"2026-01-30T02:29:23.494127Z","published":"2022-07-15T05:17:35Z","related":["CVE-2021-4178"],"database_specific":{"cwe_ids":["CWE-502","CWE-94"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-15T05:17:35Z","nvd_published_at":"2022-08-24T16:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4178"},{"type":"WEB","url":"https://github.com/fabric8io/kubernetes-client/issues/3653"},{"type":"WEB","url":"https://github.com/fabric8io/kubernetes-client/commit/445103004d1ed3153d5abb272473451d05891e39"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2021-4178"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2034388"},{"type":"PACKAGE","url":"https://github.com/fabric8io/kubernetes-client"},{"type":"WEB","url":"https://www.mend.io/vulnerability-database/CVE-2021-4178"}],"affected":[{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0-beta-1"},{"fixed":"5.0.3"}]}],"versions":["5.0.0","5.0.0-beta-1","5.0.1","5.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}},{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.1.2"}]}],"versions":["5.1.0","5.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}},{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"5.3.2"}]}],"versions":["5.2.0","5.2.1","5.3.0","5.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}},{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.7.4"}]}],"versions":["5.5.0","5.6.0","5.7.0","5.7.1","5.7.2","5.7.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}},{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.8.0"},{"fixed":"5.8.1"}]}],"versions":["5.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}},{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.9.0"},{"fixed":"5.10.2"}]}],"versions":["5.10.0","5.10.1","5.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}},{"package":{"name":"io.fabric8:kubernetes-client","ecosystem":"Maven","purl":"pkg:maven/io.fabric8/kubernetes-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.11.2"}]}],"versions":["5.11.0","5.11.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-98g7-rxmf-rrxm/GHSA-98g7-rxmf-rrxm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}