An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp9 | — | Upgrade kata-containers | Jan 5, 2021 | Nov 17, 2020 |
| Oracle_linux | — | Upgrade kata-imageUpgrade kubectlUpgrade kata-agentUpgrade kata-proxyUpgrade kubeadmUpgrade olcne-api-serverUpgrade kataUpgrade kata-shimUpgrade olcne-prometheus-chartUpgrade kubeletUpgrade olcne-nginxUpgrade olcne-utilsUpgrade kata-ksm-throttlerUpgrade kata-runtimeUpgrade olcnectlUpgrade olcne-agentUpgrade olcne-istio-chart | Feb 11, 2021 | Nov 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub