GHSA-f5f7-6478-qm6p
GitHub Security Advisory
Files or Directories Accessible to External Parties in kubernetes
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Affected Packages
Go
k8s.io/kubernetes
Affected versions:
0
(fixed in 1.19.15)
Go
k8s.io/kubernetes
Affected versions:
1.20.0
(fixed in 1.20.11)
Go
k8s.io/kubernetes
Affected versions:
1.21.0
(fixed in 1.21.5)
Go
k8s.io/kubernetes
Affected versions:
1.22.0
(fixed in 1.22.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 13, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.