CVE-2020-28914: High severity katacontainers Kata-containers vulnerability
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28914?
CVE-2020-28914 has a high severity rating of 7.1 based on the CVSS 3.1 scoring.
How do I fix CVE-2020-28914?
To fix CVE-2020-28914, upgrade to Kata Containers version 1.11.5 or later.
What systems are affected by CVE-2020-28914?
CVE-2020-28914 affects Kata Containers versions prior to 1.11.5 when using Kubernetes hostPath volumes.
What type of vulnerability is CVE-2020-28914?
CVE-2020-28914 is an improper file permissions vulnerability that allows writable access to files marked as read-only.
What is the impact of CVE-2020-28914 on container security?
CVE-2020-28914 can lead to unauthorized modifications of files within the container, compromising container integrity and security.