CVE-2021-4178

Aliases:GHSA-98g7-rxmf-rrxm
Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 24 Aug 2022, 15:02
Last modified:03 Aug 2024, 17:16

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.7 MEDIUM
v3.1 (nvd)
EPSS Score
0.24% LOW
0% probability +0.15%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Aug 2022, 15:02
Published
Vulnerability first disclosed
03 Aug 2024, 17:16
Last Modified
Vulnerability information updated

Description

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

CVSS Metrics

  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.24% Percentile: 48%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • io.fabric8kubernetes-client

    ≥ 5.0.0-beta-1, < 5.0.3 | ≥ 5.1.0, < 5.1.2 | ≥ 5.2.0, < 5.3.2 | ≥ 5.5.0, < 5.7.4 | ≥ 5.8.0, < 5.8.1 | ≥ 5.9.0, < 5.10.2 | ≥ 5.11.0, < 5.11.2

  • redhata-mq_streams

    2.0.1

  • redhatbuild_of_quarkus

    2.2.5

  • redhatdescision_manager

    7.0

  • redhatfabric8-kubernetes

    ≥ 5.0.1, < 5.0.3 | ≥ 5.1.0, < 5.1.2 | ≥ 5.2.0, < 5.3.2 | ≥ 5.5.0, < 5.7.4 | ≥ 5.9.0, < 5.10.2 | ≥ 5.11.0, < 5.11.2 | 5.0.0:beta1 | 5.8.0

  • redhatfuse

    7.11

  • redhatintegration_camel_k

    na

  • redhatintegration_camel_quarkus

    2.2.1

  • redhatopenshift_application_runtimes

    na

  • redhatprocess_automation

    7.0

References (9)