← Vulnerability feed

Vulnerability record · CVE-2021-20218 · published 16 March 2021

CVE-2021-20218: Redhat kubernetes-client path traversal vulnerability

Redhat · Kubernetes Client

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2

7.4 CVSS 3.1 High EPSS 1.3% · top 30.3% CWE-22 · Path traversal
7.4CVSS 3.1 base score, v2 5.8
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2022-4116Redhat build of quarkus vulnerabilityA vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to…EPSS 33%9.1CVE-2023-6394Quarkus missing authorization vulnerabilityA flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…EPSS 0.81%8.1CVE-2023-4853Quarkus incorrect authorization vulnerabilityA flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…EPSS 1.4%8.1CVE-2023-2974Redhat build of quarkus vulnerabilityA vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enfor…EPSS 0.88%7.8CVE-2022-1011Linux kernel use after free vulnerabilityA use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unaut…EPSS 1.2%7.5CVE-2024-7885Redhat build of apache camel - hawtio race condition vulnerabilityA vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…EPSS 2.6%7.5CVE-2022-4244Codehaus-plexus plexus-utils path traversal vulnerabilityA flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2021-20218), CISA KEV, FIRST EPSS (scores of 2026-10-04). This page is refreshed as NVD updates the record.