← Back

CVE-2021-25741

nvd nist
Published: Sep 20, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

Affected (4)

1 product
Kubernetes
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
Up to 1.19.14
From 1.20.0 to 1.20.10
From 1.21.0 to 1.21.4
From 1.22.0 to 1.22.1

References (6)

Source: jordan@liggitt.net
MitigationThird Party Advisory
Source: jordan@liggitt.net
Mailing ListMitigation
Source: jordan@liggitt.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigation
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.