Files or Directories Accessible to External Parties in kubernetes
High severity
GitHub Reviewed
Published
Sep 17, 2021
in
bottlerocket-os/bottlerocket
•
Updated Feb 1, 2023
Package
Affected versions
< 1.19.15
>= 1.20.0, < 1.20.11
>= 1.21.0, < 1.21.5
>= 1.22.0, < 1.22.2
Patched versions
1.19.15
1.20.11
1.21.5
1.22.2
Description
Published by the National Vulnerability Database
Sep 20, 2021
Reviewed
Nov 1, 2021
Published to the GitHub Advisory Database
Nov 1, 2021
Last updated
Feb 1, 2023
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
References