CVE-2021-25741

HIGH8.1EPSS 33.0%

Files or Directories Accessible to External Parties in kubernetes

Published: 11/1/2021Modified: 2/4/2026
Also known as:GHSA-f5f7-6478-qm6pCGA-w3f5-75v2-fp9fGO-2022-0910

Description

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

References (7)