Lucene search

K
ibmIBM70F75E7524B1704D6EBDE338C1A5FB98016CEEF82A02C5FBED49E65AC60CF084
HistoryJul 05, 2022 - 11:14 a.m.

Security Bulletin: IBM Event Streams is vulnerable to arbitrary code execution due to the Fabric8 Kubernetes client (CVE-2021-4178)

2022-07-0511:14:46
www.ibm.com
16

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.0%

Summary

There is a vulnerability in the Fabric8 Kubernetes client. The library is used by IBM Event Streams.

Vulnerability Details

CVEID:CVE-2021-4178
**DESCRIPTION:**Fabric8 Kubernetes client could allow a local authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization due to improperly configured YAML parsing. By using a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 6.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/222690 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams

10.4.0, 10.5.0, 11.0.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading

IBM Event Streams (Continuous Delivery)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmevent_streamsMatch10.4.0
OR
ibmevent_streamsMatch10.5.0
OR
ibmevent_streamsMatch11.0.0

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.0%

Related for 70F75E7524B1704D6EBDE338C1A5FB98016CEEF82A02C5FBED49E65AC60CF084