Skip to content

kubernetes CVE-2021-25741

High
tjkirch published GHSA-f5f7-6478-qm6p Sep 17, 2021

Package

kubernetes (bottlerocket)

Affected versions

< 1.2.1

Patched versions

1.2.1

Description

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

kubernetes/kubernetes#104980

Severity

High

CVE ID

CVE-2021-25741

Weaknesses

No CWEs