A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://groups.google.com/g/kubernetes-security-announce/c/nyfdhK24H7s | mailing list mitigation |
https://github.com/kubernetes/kubernetes/issues/104980 | third party advisory mitigation |
https://security.netapp.com/advisory/ntap-20211008-0006/ | third party advisory |