CVE-2020-27151
07.12.2020, 14:15
An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.Enginsight
Vendor | Product | Version |
---|---|---|
katacontainers | kata_containers | 𝑥 ≤ 1.11.3 |
katacontainers | kata_containers | 2.0.0:alpha1 |
katacontainers | kata_containers | 2.0.0:alpha2 |
katacontainers | kata_containers | 2.0.0:alpha3 |
katacontainers | kata_containers | 2.0.0:rc0 |
katacontainers | kata_containers | 2.0.0:rc1 |
𝑥
= Vulnerable software versions
References