First published: Mon Aug 16 2021(Updated: )
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Credit: jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes Kubernetes | <=1.19.14 | |
Kubernetes Kubernetes | >=1.20.0<=1.20.10 | |
Kubernetes Kubernetes | >=1.21.0<=1.21.4 | |
Kubernetes Kubernetes | >=1.22.0<=1.22.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25741 is a security issue discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
The severity of CVE-2021-25741 is high, with a CVSS score of 8.1.
Kubernetes versions up to and including 1.22.1, 1.21.4, and 1.20.10 are affected by CVE-2021-25741.
To fix CVE-2021-25741, update your Kubernetes installation to version 1.22.2, 1.21.5, or 1.20.11, depending on your currently deployed version.
You can find more information about CVE-2021-25741 in the GitHub issue and Red Hat security advisories linked in the references.