{
  "schema_version": "1.4.0",
  "id": "GHSA-cghx-9gcr-r42x",
  "modified": "2022-10-07T20:36:09Z",
  "published": "2021-01-29T18:12:54Z",
  "aliases": [
    "CVE-2020-8570"
  ],
  "summary": "Path Traversal in the Java Kubernetes Client",
  "details": "Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Maven",
        "name": "io.kubernetes:client-java"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "9.0.2"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "io.kubernetes:client-java"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "10.0.0"
            },
            {
              "fixed": "10.0.1"
            }
          ]
        }
      ],
      "versions": [
        "10.0.0"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8570"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kubernetes-client/java/issues/1491"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kubernetes-client/java/pull/1450"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kubernetes-client/java/commit/858316ae8bc1145005a0310e1f65f95d2389a589"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/kubernetes-client/java"
    },
    {
      "type": "WEB",
      "url": "https://groups.google.com/g/kubernetes-security-announce/c/sd5h73sFPrg"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40@%3Ccommits.druid.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942@%3Ccommits.druid.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3@%3Ccommits.druid.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6@%3Ccommits.druid.apache.org%3E"
    }
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-22"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2021-01-22T18:25:27Z",
    "nvd_published_at": "2021-01-21T17:15:00Z"
  }
}