Symlink Exchange Can Allow Host Filesystem Access
Vulnerability Description
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25741
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Fabricio Voznika & Mark Wolters
References
More from Kubernetes
View All →Affected Vendor
Kubernetes
View all reports →