Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-25741

Опубликовано: 20 сент. 2021
Источник: debian
EPSS Средний

Описание

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.5+really1.20.2-1package

Примечания

  • Server components no longer built since 1.20.5+really1.20.2-1, marking that as fixed version

  • The source package itself it still vulnerable, but custom rebuilds are not really a usecase here

  • https://github.com/kubernetes/kubernetes/issues/104980

EPSS

Процентиль: 96%
0.2784
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
redhat
почти 4 года назад

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
nvd
больше 3 лет назад

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.1
github
больше 3 лет назад

Files or Directories Accessible to External Parties in kubernetes

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость программы для оркестровки контейнеризированных приложений Kubernetes, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти введенные ограничения безопасности

EPSS

Процентиль: 96%
0.2784
Средний