Database/Container, Kubernetes & orchestration
Kubernetes (kubectl): kubectl does not neutralise ANSI escape sequences in output
CVSS 3.0CVE-2021-25743Container, Kubernetes & orchestrationcurated
Impact
kubectl does not neutralise ANSI escape sequences in output; terminal injection on the operator's machine
Who can reach it
Any tenant who can set an object field the operator will print
What to do
Upgrade kubectl on operator machines
References
Related entries
- Kubernetes (kubectl): `kubectl cp` path traversal from a malicious container tar overwrites files on the operator'sCVE-2019-11246 · Kubernetes (kubectl)Medium
- Kubernetes (kubectl): Follow-up incomplete fix for the kubectl cp traversalCVE-2019-11249 · Kubernetes (kubectl)Medium
- Kubernetes (kubectl): Double-symlink in tar output escapes the kubectl cp destinationCVE-2019-11251 · Kubernetes (kubectl)Medium
- OCI Distribution Spec: Content-Type alone determines manifest type, so a manifest can be interpreted differentlyCVE-2021-41190 · OCI Distribution SpecLow
- containerd (OCI manifest / index parsing, Content-Type handling): SUPPLY CHAIN: the image digest stops being anNCVD-2021-013-containerd-oci-manifest-index-pa · containerd (OCI manifest / index parsing, Content-Type handling)Low
- Docker / moby: `docker cp` into a crafted container changes Unix permissions of existing host filesCVE-2021-41089 · Docker / mobyLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.