kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
References
Link | Resource |
---|---|
https://github.com/kubernetes/kubernetes/issues/101695 | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220217-0003/ | Third Party Advisory |
Configurations
Information
Published : 2022-01-06 16:15
Updated : 2022-02-28 07:22
NVD link : CVE-2021-25743
Mitre link : CVE-2021-25743
JSON object : View
CWE
Products Affected
kubernetes
- kubernetes