Vulnerability Details CVE-2020-27833
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a symbolic link is first created pointing within the tarball, this allows further symbolic links to bypass the existing path check. This flaw allows the tarball to create links outside the tarball's parent directory, allowing for executables or configuration files to be overwritten, resulting in arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions up to and including openshift-clients-4.7.0-202104250659.p0.git.95881af are affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.8%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 4.6
Products affected by CVE-2020-27833
-
cpe:2.3:a:redhat:openshift_container_platform:-
-
cpe:2.3:a:redhat:openshift_container_platform:2.0
-
cpe:2.3:a:redhat:openshift_container_platform:2.1
-
cpe:2.3:a:redhat:openshift_container_platform:2.2
-
cpe:2.3:a:redhat:openshift_container_platform:3.0
-
cpe:2.3:a:redhat:openshift_container_platform:3.1
-
cpe:2.3:a:redhat:openshift_container_platform:3.10
-
cpe:2.3:a:redhat:openshift_container_platform:3.11
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.104
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.117
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.129
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.135
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.141
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.146
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.153
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.154
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.157
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.161
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.170
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.188
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.200
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.216
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.219
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.232
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.248
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.272
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.286
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.306
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.317
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.318
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.346
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.374
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.380
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.394
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.404
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.420
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.43
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.439
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.51
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.59
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.69
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.82
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.88
-
cpe:2.3:a:redhat:openshift_container_platform:3.11.98
-
cpe:2.3:a:redhat:openshift_container_platform:3.2
-
cpe:2.3:a:redhat:openshift_container_platform:3.3
-
cpe:2.3:a:redhat:openshift_container_platform:3.4
-
cpe:2.3:a:redhat:openshift_container_platform:3.5
-
cpe:2.3:a:redhat:openshift_container_platform:3.6
-
cpe:2.3:a:redhat:openshift_container_platform:3.7
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.14
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.23
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.42-2
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.44
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.46
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.52
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.53
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.54
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.57
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.61
-
cpe:2.3:a:redhat:openshift_container_platform:3.8
-
cpe:2.3:a:redhat:openshift_container_platform:3.9
-
cpe:2.3:a:redhat:openshift_container_platform:3.9.31
-
cpe:2.3:a:redhat:openshift_container_platform:4.0
-
cpe:2.3:a:redhat:openshift_container_platform:4.1
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.11
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.13
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.14
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.15
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.16
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.17
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.18
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.2
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.20
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.21
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.22
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.23
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.24
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.25
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.26
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.27
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.28
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.29
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.3
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.30
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.31
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.34
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.38
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.4
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.41
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.6
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.7
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.8
-
cpe:2.3:a:redhat:openshift_container_platform:4.1.9
-
cpe:2.3:a:redhat:openshift_container_platform:4.2
-
cpe:2.3:a:redhat:openshift_container_platform:4.3
-
cpe:2.3:a:redhat:openshift_container_platform:4.4
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.10
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.11
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.12
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.13
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.14
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.15
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.16
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.17
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.18
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.19
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.20
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.21
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.23
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.26
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.27
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.29
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.3
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.30
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.31
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.32
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.33
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.4
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.5
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.6
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.8
-
cpe:2.3:a:redhat:openshift_container_platform:4.4.9
-
cpe:2.3:a:redhat:openshift_container_platform:4.5
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.11
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.13
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.14
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.15
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.16
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.17
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.18
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.19
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.2
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.20
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.21
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.22
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.23
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.24
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.27
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.28
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.3
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.30
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.31
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.33
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.34
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.35
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.36
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.37
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.38
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.39
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.4
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.5
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.6
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.7
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.8
-
cpe:2.3:a:redhat:openshift_container_platform:4.5.9
-
cpe:2.3:a:redhat:openshift_container_platform:4.6
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.1
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.12
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.13
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.15
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.16
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.17
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.18
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.19
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.20
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.21
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.22
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.23
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.25
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.26
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.27
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.28
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.29
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.3
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.30
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.31
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.32
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.34
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.35
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.36
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.38
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.39
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.4
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.40
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.41
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.42
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.43
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.44
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.45
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.46
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.47
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.48
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.49
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.51
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.52
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.53
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.54
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.55
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.56
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.57
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.58
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.59
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.6
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.60
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.61
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.8
-
cpe:2.3:a:redhat:openshift_container_platform:4.6.9
-
cpe:2.3:a:redhat:openshift_container_platform:4.7