Описание
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Issue TrackingMitigationVendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Issue TrackingMitigationVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
8.8 High
CVSS3
9.6 Critical
CVSS3
5.5 Medium
CVSS2
Дефекты
Связанные уязвимости
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to version ...
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
EPSS
8.8 High
CVSS3
9.6 Critical
CVSS3
5.5 Medium
CVSS2