PT-2025-35146 · Unknown+1 · Mysql Server+3

Nobuto-M

·

Published

2025-08-28

·

Updated

2025-08-29

·

CVE-2025-58061

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEBS versions prior to 0.10.0
Description OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world readable, potentially allowing non-privileged users to access sensitive data. The rawfile-localpv storage class creates persistent volume data under /var/csi/rawfile/ on Kubernetes hosts by default, but the directory and data within it are world-readable. This could lead to a database breach if Kubernetes tenants are running databases like MySQL or PostgreSQL in containers.
Recommendations Upgrade to version 0.10.0 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-58061
GHSA-WH95-VW4R-XWX4

Affected Products

Kubernetes
Mysql Server
Openebs
Postgresql