PT-2021-5366 · Unknown+2 · Kubernetes+1

Fabricio Voznika

+1

·

Published

2021-09-15

·

Updated

2025-08-08

·

CVE-2021-25741

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kubernetes (affected versions not specified)
Description A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. The issue is related to insufficient access control and can be exploited by a remote attacker to bypass security restrictions. The problem is caused by a race condition that allows an attacker to create a symbolic link, giving access from the container to the root of the operating system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Files Accessible to External Parties

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3453
ALT-PU-2021-3547
ALT-PU-2022-1245
BDU:2021-06196
CVE-2021-25741
ELSA-2021-9526
ELSA-2021-9546
GHSA-F5F7-6478-QM6P
GO-2022-0910
OPENSUSE-SU-2025:15424-1
RHSA-2021:3631
RHSA-2021:3635
RHSA-2021:3642
RHSA-2021:3646

Affected Products

Alt Linux
Kubernetes