{"id":"CVE-2017-1002101","details":"In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.","modified":"2026-02-03T06:54:56.717651Z","published":"2018-03-13T17:29:00.233Z","related":["openSUSE-SU-2020:0554-1","openSUSE-SU-2024:10901-1"],"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0475"},{"type":"ADVISORY","url":"https://github.com/bgeesaman/subpath-exploit/"},{"type":"ADVISORY","url":"https://github.com/kubernetes/kubernetes/issues/60813"},{"type":"REPORT","url":"https://github.com/kubernetes/kubernetes/issues/60813"},{"type":"EVIDENCE","url":"https://github.com/bgeesaman/subpath-exploit/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kubernetes/kubernetes","events":[{"introduced":"0b9efaeb34a2fc51ff8e4d34ad9bc6375459c4a4"},{"fixed":"3fb1aafdafa3d33bc698930095db1e56c0f76452"},{"introduced":"925c127ec6b946659ad0fd596fa959be43f0cc05"},{"fixed":"bee2d1505c4fe820744d26d41ecd3fdd4a3d6546"},{"introduced":"d3ada0119e776222f11ec7945e6d860061339aad"},{"fixed":"d1303b003001cf2b5b8cec099383125096b3dac0"}]}],"versions":["v1.7.0","v1.7.1","v1.7.1-beta.0","v1.7.10","v1.7.10-beta.0","v1.7.11","v1.7.11-beta.0","v1.7.12","v1.7.12-beta.0","v1.7.13","v1.7.13-beta.0","v1.7.14-beta.0","v1.7.2","v1.7.2-beta.0","v1.7.3","v1.7.3-beta.0","v1.7.4","v1.7.4-beta.0","v1.7.5","v1.7.5-beta.0","v1.7.6","v1.7.6-beta.0","v1.7.7","v1.7.7-beta.0","v1.7.8","v1.7.8-beta.0","v1.7.9","v1.7.9-beta.0","v1.8.0","v1.8.1","v1.8.1-beta.0","v1.8.2","v1.8.2-beta.0","v1.8.3","v1.8.3-beta.0","v1.8.4","v1.8.4-beta.0","v1.8.5","v1.8.5-beta.0","v1.8.6","v1.8.6-beta.0","v1.8.7","v1.8.7-beta.0","v1.8.8","v1.8.8-beta.0","v1.8.9-beta.0","v1.9.0","v1.9.1","v1.9.1-beta.0","v1.9.2","v1.9.2-beta.0","v1.9.3","v1.9.3-beta.0","v1.9.4-beta.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1002101.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}