← Back

CVE-2021-25743

nvd nist
Published: Jan 7, 2022Modified: Jun 17, 2026

JSON object

Loading...
3.0
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Exploitability: 1.3 / Impact: 1.4
Source: NVD

Description

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

Affected (4)

1 product
Kubernetes
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
Up to 1.25.0
Version 1.26.0 alpha0
Version 1.26.0 alpha1
Version 1.26.0 alpha2

References (4)

Source: jordan@liggitt.net
Vendor Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.