Vulnerabilities > CVE-2021-25741 - Files or Directories Accessible to External Parties vulnerability in Kubernetes
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/kubernetes/kubernetes/issues/104980
- https://github.com/kubernetes/kubernetes/issues/104980
- https://groups.google.com/g/kubernetes-security-announce/c/nyfdhK24H7s
- https://groups.google.com/g/kubernetes-security-announce/c/nyfdhK24H7s
- https://security.netapp.com/advisory/ntap-20211008-0006/
- https://security.netapp.com/advisory/ntap-20211008-0006/