Loading HuntDB...

GHSA-f5f7-6478-qm6p

GitHub Security Advisory

Files or Directories Accessible to External Parties in kubernetes

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

Affected Packages

Go k8s.io/kubernetes
Affected versions: 0 (fixed in 1.19.15)
Go k8s.io/kubernetes
Affected versions: 1.20.0 (fixed in 1.20.11)
Go k8s.io/kubernetes
Affected versions: 1.21.0 (fixed in 1.21.5)
Go k8s.io/kubernetes
Affected versions: 1.22.0 (fixed in 1.22.2)

Related CVEs

Key Information

GHSA ID
GHSA-f5f7-6478-qm6p
Published
November 1, 2021 5:32 PM
Last Modified
November 1, 2021 5:26 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
k8s.io/kubernetes
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.