NA

CVE-2021-4178

Published: 24/08/2022 Updated: 04/10/2022
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged malicious user to supply malicious YAML.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat fabric8-kubernetes

redhat fabric8-kubernetes 5.8.0

redhat fabric8-kubernetes 5.0.0

redhat process automation 7.0

redhat openshift application runtimes -

redhat descision manager 7.0

redhat integration camel k -

redhat a-mq streams 2.0.1

redhat fuse 7.11

redhat integration camel quarkus 2.2.1

redhat build of quarkus 2.2.5

Vendor Advisories

Synopsis Moderate: Red Hat build of Quarkus 225 release and security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat build of QuarkusRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...
Synopsis Moderate: Red Hat Integration Camel Extensions for Quarkus 221 security update Type/Severity Security Advisory: Moderate Topic A security update to Red Hat Integration Camel Extensions for Quarkus 22 is now available The purpose of this text-only errata is to inform you about the security issues fixedRed Hat Product Security has ...
Synopsis Moderate: Red Hat support for Spring Boot 272 update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Application Runtimes Description Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths an ...
Synopsis Important: jenkins and jenkins-2-plugins security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for ...
Synopsis Important: Red Hat Fuse 7110 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 710 to 711) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...
Synopsis Important: Red Hat AMQ Streams 167 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Streams 167 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: Red Hat AMQ Streams 201 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Streams 201 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 500-beta-1 and above Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML ...