CVE-2021-25743
LOW 3.0EPSS 0.8%
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
- CVSS v3.1
- 3.0 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N - CVSS v3.1
- 3.0 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N - CVSS v3.1
- 3.0 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N - CVSS v2.0
- 2.1 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:N - EPSS
- 0.78% chance of exploitation in the next 30 days, 53th percentile
- Published
- 2022-01-07
- Updated
- 2024-09-16
Proof-of-concept exploits (1)
- dgl/houdini-kubectl-poc9★ · 2023-03-14