
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN009
_____________________________________________________________________

DATE                : 12/01/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Kubernetes Java Client versions
                             prior to 9.0.2, 10.0.1, 11.0.0.

=====================================================================
https://groups.google.com/g/kubernetes-announce/c/8-bsKoI_KX0
_____________________________________________________________________


Hello Kubernetes Community,

A security issue was discovered in Kubernetes Java Client that could
overwrite files outside of the current directory when copying files from
a Pod.

This issue has assigned CVE-2020-8570.
Am I vulnerable?

If you are not using the Java client for Kubernetes, you are not impacted.

If you are not using Copy in the Java client for Kubernetes, you are not
impacted.

If you are using Copy and you have upgraded to 9.0.2, 10.0.1 or 11.0.0
you are not impacted.

Otherwise, if you are using Copy with an older version of the Java
client and you are copying from untrusted Pods you may be impacted.
Affected Versions

    All versions prior to 9.0.2
    Version 10.0.0

How do I mitigate this vulnerability?

ACTION REQUIRED: Upgrade to 9.0.2, 10.0.1 or 11.0.0

Prior to upgrading, this vulnerability can be mitigated by not Copying
files from untrusted Pods
Fixed Versions

    9.0.2
    10.0.1
    11.0.0

Detection

If you find evidence that this vulnerability has been exploited, please
contact secu...@kubernetes.io
Additional Details

See the GitHub issue for more details:
https://github.com/kubernetes-client/java/issues/1491
Acknowledgements

This vulnerability was reported by CodeQL Automated scanning by GitHub

Thank You,

Brendan Burns

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================



