{"id":"CVE-2020-8570","details":"Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.","aliases":["GHSA-cghx-9gcr-r42x"],"modified":"2026-08-07T15:15:00.852050Z","published":"2021-01-21T17:15:14.327Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6%40%3Ccommits.druid.apache.org%3E"},{"type":"ADVISORY","url":"https://groups.google.com/g/kubernetes-security-announce/c/sd5h73sFPrg"},{"type":"FIX","url":"https://github.com/kubernetes-client/java/issues/1491"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kubernetes-client/java","events":[{"introduced":"0"},{"fixed":"6267ff3cb7ad12984bd1a9aec96ee3b075da460b"},{"introduced":"f68f17720e153bf5ddca6e63df70477c776e765f"},{"fixed":"6267ff3cb7ad12984bd1a9aec96ee3b075da460b"}],"database_specific":{"cpe":"cpe:2.3:a:kubernetes:java:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"9.0.2"},{"introduced":"10.0.0"},{"fixed":"10.0.1"}],"source":"CPE_RANGE"}}],"versions":["client-java-parent-8.0.1","client-java-parent-6.0.1","client-java-parent-2.0.0","client-java-parent-2.0.0-beta2","client-java-parent-1.0.0-beta3","client-java-parent-1.0.0-beta2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8570.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}