« Volver al listado

CVE-2021-25743

Estado: AnalizadaBaja (3)—

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-25743",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "jordan@liggitt.net",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 3,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 3,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "jordan@liggitt.net",
      "affectedData": [
        {
          "vendor": "Kubernetes",
          "product": "Kubernetes",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "1.23.1"
            },
            {
              "status": "unknown",
              "version": "next of 1.23.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "1.22.5"
            },
            {
              "status": "unknown",
              "version": "next of 1.22.5",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "1.21.8"
            },
            {
              "status": "unknown",
              "version": "next of 1.21.8",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "1.20.14"
            },
            {
              "status": "unknown",
              "version": "next of 1.20.14",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-01-07T00:15:07.817",
  "references": [
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/101695",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20220217-0003/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/101695",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20220217-0003/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "jordan@liggitt.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-150"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events."
    },
    {
      "lang": "es",
      "value": "kubectl no neutraliza las secuencias de escape, meta o de control contenidas en los datos brutos que envía a un terminal. Esto incluye, pero no se limita, a los campos de cadena no estructurados en objetos como los Eventos"
    }
  ],
  "lastModified": "2026-06-17T03:42:23.367",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F8AC6E5-6AF8-4881-A2F6-65BD2FC6D58A",
              "versionEndIncluding": "1.25.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:kubernetes:1.26.0:alpha0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A624A6DA-8037-474D-B2AB-9CFC8B0528F3"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:kubernetes:1.26.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13839708-E353-4757-9638-90CFE181B8B0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:kubernetes:1.26.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B7CC489-4E29-46BA-9BB9-C30F0E512DDF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jordan@liggitt.net"
}