CVE-2021-25743

LOW3.0EPSS 0.28%

ANSI escape characters not filtered in kubectl in k8s.io/kubernetes

Published: 1/8/2022Modified: 4/28/2026

Description

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.0CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

References (8)