PT-2025-35146 · Unknown+1 · Mysql Server+3

Nobuto-M

·

Publicado

2025-08-28

·

Atualizado

2025-08-29

·

CVE-2025-58061

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEBS versions prior to 0.10.0
Description OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world readable, potentially allowing non-privileged users to access sensitive data. The rawfile-localpv storage class creates persistent volume data under /var/csi/rawfile/ on Kubernetes hosts by default, but the directory and data within it are world-readable. This could lead to a database breach if Kubernetes tenants are running databases like MySQL or PostgreSQL in containers.
Recommendations Upgrade to version 0.10.0 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-58061
GHSA-WH95-VW4R-XWX4

Produtos afetados

Kubernetes
Mysql Server
Openebs
Postgresql