Описание
Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
FAQ
How could an attacker exploit this vulnerability?
An attacker who can run an untrusted container configured with hostNetwork could send specially crafted requests to a host‑level service that was not intended for unauthenticated access. This could allow the attacker to break out of the container and gain control of the AKS worker node.
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Azure Kubernetes Service |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
8.8 High
CVSS3
Связанные уязвимости
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
Уязвимость служба для развертывания контейнерных приложений и управления ими Azure Kubernetes Service (AKS), связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3