CVE-2021-25743
3.0
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Exploitability: 1.3 / Impact: 1.4
Source: NVD
Description
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
Affected (4)
Products: Kubernetes: Kubernetes
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.25.0 |
References (4)
Source: jordan@liggitt.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.