peter bassill · operator
$ cve CVE-2020-8570 JSON

CVE-2020-8570

9.1
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS3.64% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-23
On CISA KEVno
Public exploitnone known
Published2021-01-21
Last modified2026-06-17

Affected (1)

VendorProduct
kubernetesjava

References

→ the Explorer  ·  watch your stack  ·  NVD