Back to search
CVE-2021-25743
Published: Jan 7, 2022
Modified: Sep 16, 2024
PUBLISHED
CVSS v3.1
3.0
LOW
Description
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
| Vendor | Product | Versions |
|---|---|---|
Kubernetes | Kubernetes | affected unspecified - <= 1.23.1unknown next of 1.23.1 - < unspecifiedaffected unspecified - <= 1.22.5unknown next of 1.22.5 - < unspecifiedaffected unspecified - <= 1.21.8+3 more versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None
References
https://github.com/kubernetes/kubernetes/issues/101695
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20220217-0003/
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now