Vulnerability Report: GO-2022-0701
- CVE-2015-5305, GHSA-jp32-vmm6-3vf5
- Affects: k8s.io/kubernetes
- Published: Feb 15, 2022
- Modified: Jul 19, 2024
Crafted object type names can cause directory traversal in Kubernetes. Object names are not validated before being passed to etcd. This allows attackers to write arbitrary files via a crafted object name, hence causing directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.1.1
-
before v1.1.1
-
before v1.1.1
-
before v1.1.1
-
before v1.1.1
-
before v1.1.1
Aliases
References
- https://github.com/kubernetes/kubernetes/pull/16381
- https://github.com/kubernetes/kubernetes/commit/37f730f68c7f06e060f90714439bfb0dbb2df5e7
- https://vuln.go.dev/ID/GO-2022-0701.json
Credits
- liggitt (Jordan Liggitt)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.