GO-2022-0782
Dashboard / Vulnerabilities / GO-2022-0782
Summary: Symlink Attack in kubectl cp in k8s.io/kubernetes
Details: Symlink Attack in kubectl cp in k8s.io/kubernetes
References: https://github.com/advisories/GHSA-34jx-wx69-9x8v, http://www.openwall.com/lists/oss-security/2019/06/21/1, http://www.openwall.com/lists/oss-security/2019/08/05/5, https://access.redhat.com/errata/RHBA-2019:0619, https://access.redhat.com/errata/RHBA-2019:0620, https://access.redhat.com/errata/RHBA-2019:0636, https://github.com/kubernetes/kubernetes/commit/47063891dd782835170f500a83f37cc98c3c1013, https://github.com/kubernetes/kubernetes/pull/75037, https://lists.fedoraproject.org/archives/list/[email protected]/message/BPV2RE5RMOGUVP5WJMXKQJZUBBLAFZPZ, https://lists.fedoraproject.org/archives/list/[email protected]/message/QZB7E3DOZ5WDG46XAIU6K32CXHXPXB2F, https://www.twistlock.com/labs-blog/disclosing-directory-traversal-vulnerability-kubernetes-copy-cve-2019-1002101
Affected packages
Package
Name: k8s.io/kubernetes
Purl: pkg:golang/k8s.io/kubernetes
Affected ranges
Type: SEMVER
Events:
