Lucene search

K
nvd[email protected]NVD:CVE-2021-4178
HistoryAug 24, 2022 - 4:15 p.m.

CVE-2021-4178

2022-08-2416:15:09
CWE-502
web.nvd.nist.gov
arbitrary code execution
flaw
fabric 8 kubernetes
versions 5.0.0-beta-1
improperly configured
yaml parsing
local attacker
privileged
malicious

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.0%

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

Affected configurations

NVD
Node
redhatfabric8-kubernetesRange5.0.15.0.3
OR
redhatfabric8-kubernetesRange5.1.05.1.2
OR
redhatfabric8-kubernetesRange5.2.05.3.2
OR
redhatfabric8-kubernetesRange5.5.05.7.4
OR
redhatfabric8-kubernetesRange5.9.05.10.2
OR
redhatfabric8-kubernetesRange5.11.05.11.2
OR
redhatfabric8-kubernetesMatch5.0.0beta1
OR
redhatfabric8-kubernetesMatch5.8.0
Node
redhata-mq_streamsMatch2.0.1
OR
redhatbuild_of_quarkusMatch2.2.5
OR
redhatdescision_managerMatch7.0
OR
redhatfuseMatch7.11
OR
redhatintegration_camel_kMatch-
OR
redhatintegration_camel_quarkusMatch2.2.1
OR
redhatopenshift_application_runtimesMatch-
OR
redhatprocess_automationMatch7.0

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.0%