[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[oss-security] [kubernetes] CVE-2021-25741: Symlink Exchange Can Allow Host Filesystem Access
Hello Kubernetes Community,
A security issue was discovered in Kubernetes where a user may be able to
create a container with subpath volume mounts to access files & directories
outside of the volume, including on the host filesystem.
This issue has been rated High (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
and assigned CVE-2021-25741.
Affected Components and Configurations
This bug affects kubelet.
Environments where cluster administrators have restricted the ability to
create hostPath mounts are the most seriously affected. Exploitation allows
hostPath-like access without use of the hostPath feature, thus bypassing
In a default Kubernetes environment, exploitation could be used to obscure
misuse of already-granted privileges.
v1.22.0 - v1.22.1
v1.21.0 - v1.21.4
v1.20.0 - v1.20.10
This issue is fixed in the following versions:
To mitigate this vulnerability without upgrading kubelet, you can disable
the VolumeSubpath feature gate on kubelet and kube-apiserver, and remove
any existing Pods making use of the feature.
You can also use admission control to prevent less-trusted users from
running containers as root to reduce the impact of successful exploitation.
If you find evidence that this vulnerability has been exploited, please
contact security AT kubernetes.io
See Kubernetes Issue #104980
<https://github.com/kubernetes/kubernetes/issues/104980> for more details.
This vulnerability was reported by Fabricio Voznika and Mark Wolters of
Thanks as well to Ian Coldwater, Duffie Cooley, Brad Geesaman, and Rory
McCune for the thorough security research that led to the discovery of this
CJ Cullen on behalf of the Kubernetes Security Response Committee