Описание
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
It was found that volume security can be sidestepped with innocent emptyDir and subpath. This could give an attacker with access to a pod full control over the node host by gaining access to docker socket.
Отчет
This flaw allows a pod to mount any part of the host filesystem. The pod will run with the security contraints placed on the user but could read anything with o=rx mode and appropriate SELinux label.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | kubernetes | Will not fix | ||
Red Hat Storage 3 | heketi | Not affected | ||
Red Hat OpenShift Container Platform 3.3 | atomic-openshift | Fixed | RHSA-2018:0475 | 12.03.2018 |
Red Hat OpenShift Container Platform 3.4 | atomic-openshift | Fixed | RHSA-2018:0475 | 12.03.2018 |
Red Hat OpenShift Container Platform 3.5 | atomic-openshift | Fixed | RHSA-2018:0475 | 12.03.2018 |
Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Fixed | RHSA-2018:0475 | 12.03.2018 |
Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Fixed | RHSA-2018:0475 | 12.03.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.2 High
CVSS3
Связанные уязвимости
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to version ...
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
EPSS
7.2 High
CVSS3