# Fwd: \[Security Advisory\] CVE-2020-8570: Path Traversal bug in the Java Kubernetes Client

**URL:** <https://discuss.kubernetes.io/t/fwd-security-advisory-cve-2020-8570-path-traversal-bug-in-the-java-kubernetes-client/14435>\
**Category:** Announcements\
**Created:** [January 12, 2021, 1:13am UTC](https://discuss.kubernetes.io/t/fwd-security-advisory-cve-2020-8570-path-traversal-bug-in-the-java-kubernetes-client/14435 "2021-01-12T01:13:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![tallclair](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/tallclair/32/3516_2.png) [@tallclair](https://discuss.kubernetes.io/u/tallclair)\
**Post date:** [January 12, 2021, 1:13am UTC](https://discuss.kubernetes.io/t/fwd-security-advisory-cve-2020-8570-path-traversal-bug-in-the-java-kubernetes-client/14435/1 "2021-01-12T01:13:23Z")

</div>

Hello Kubernetes Community,

A security issue was discovered in Kubernetes Java Client that could overwrite files outside of the current directory when copying files from a Pod.

This issue has assigned CVE-2020-8570.

### Am I vulnerable?

_If you are not using the Java client for Kubernetes, you are not impacted._

_If you are not using Copy in the Java client for Kubernetes, you are not impacted._

_If you are using Copy and you have upgraded to 9.0.2, 10.0.1 or 11.0.0 you are not impacted._

_Otherwise, if you are using Copy with an older version of the Java client and you are copying from untrusted Pods you may be impacted._

#### Affected Versions- All versions prior to 9.0.2

- Version 10.0.0

### How do I mitigate this vulnerability?

**ACTION REQUIRED:** Upgrade to 9.0.2, 10.0.1 or 11.0.0

Prior to upgrading, this vulnerability can be mitigated by not Copying files from untrusted Pods

#### Fixed Versions- 9.0.2

- 10.0.1
- 11.0.0

Detection

If you find evidence that this vulnerability has been exploited, please contact [security@kubernetes.io](mailto:security@kubernetes.io)

#### Additional Details

See the GitHub issue for more details: [https://github.com/kubernetes-client/java/issues/1491](https://github.com/kubernetes-client/java/issues/1491)

#### Acknowledgements

This vulnerability was reported by CodeQL Automated scanning by GitHub

Thank You,

Brendan Burns
