{"id":"CVE-2021-20218","aliases":["GHSA-jwh2-ffg4-48xc"],"url":"https://o3.security/vulnerability/CVE-2021-20218","summary":"Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client","details":"A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2","published":"2021-03-16T21:15:10.930Z","modified":"2026-07-08T05:56:42.156326522Z","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.fabric8:kubernetes-client","fixedVersion":"4.7.2"},{"ecosystem":"Maven","name":"io.fabric8:kubernetes-client","fixedVersion":"4.11.2"},{"ecosystem":"Maven","name":"io.fabric8:kubernetes-client","fixedVersion":"4.13.2"},{"ecosystem":"Maven","name":"io.fabric8:kubernetes-client","fixedVersion":"5.0.2"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1923405"},{"type":"FIX","url":"https://github.com/fabric8io/kubernetes-client/issues/2715"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:56:42.156326522Z"}}