An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HKatacontainers Kata Containers
APPKatacontainers2.0.0≤ 1.11.3
Related vulnerabilities
Kata Containers: modyfikacja systemu plików VM umożliwia RCE jako root
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine...
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine...
Kata Containers to projekt open source implementujący lekkie Virtual Machines działające jak kontenery. Wersje...
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes ho...