Insecure session management In kubernetes
Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1.7.16+dfsg-1 | ||
debian 14 | 1.7.16+dfsg-1 | ||
debian 13 | 1.7.16+dfsg-1 | ||
go | v1.3.11, v1.5.9, v1.6.14, v1.7.14, v1.8.9, v1.9.4 | ||
debian 12 | 1.7.16+dfsg-1 | ||
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2.