Popis
K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s-s etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can be written to arbitrary locations on the filesystem when an administrator restores the archive as a compressed etcd snapshot. This vulnerability is fixed in 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1.
CVSS 5.8EPSS 0.122%Riziko 0.59
Zobraziť zdroj- Zverejnené
- 2026-06-25 19:16:41
- Dotknuté verzie
- cannotmatch
- Typ
- Kritický softvér
- Vektor
- CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H