CVE-2021-25741: Symlink Exchange Can Allow Host Filesystem Access
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Other sources
Symlink Exchange Can Allow Host Filesystem Access
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25741?
CVE-2021-25741 is a security issue discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
What is the severity of CVE-2021-25741?
The severity of CVE-2021-25741 is high, with a CVSS score of 8.1.
Which versions of Kubernetes are affected by CVE-2021-25741?
Kubernetes versions up to and including 1.22.1, 1.21.4, and 1.20.10 are affected by CVE-2021-25741.
How can I fix CVE-2021-25741?
To fix CVE-2021-25741, update your Kubernetes installation to version 1.22.2, 1.21.5, or 1.20.11, depending on your currently deployed version.
Where can I find more information about CVE-2021-25741?
You can find more information about CVE-2021-25741 in the GitHub issue and Red Hat security advisories linked in the references.