An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.
Related Articles
All Mix →Time to Switch From Debit to Credit When Paying for Things?
I tend to prefer debit when purchasing things. It hasn’t really been a security thing for me; it’s been more of a speed issue. But…
About eggs and baskets – password managers
Table of Contents All eggs in one basket, is it really a problem? We're putting all eggs in one basket anyway Conclusion This tweet from…
The AI impact. A triager’s perspective
As part of our recent AI blog series, and in addition to content on ‘How AI is leveraged to enhance the Intigriti platform’, we have…
Fair and Transparent Hacker Invitations
Table of Contents Fair and Transparent Hacker Invitations Hacker Invitation Preferences Your Feedback Made The Difference We’re happy to share that, based on your feedback,…
Broken Access Control – Lab #8 UID controlled by parameter, with unpredictable UIDs | Short Version
Broken Access Control – Lab #8 UID controlled by parameter, with unpredictable UIDs | Short Version Source link
Client-Side Desync Attack (CSD)
Table of Contents 🔍 Introduction 🗡 Offensive techniques Detect Exploitation 🛡 Defensive techniques 📌 References 🔍 Introduction Client-Side Desync(CSD) Attack은 HTTP Request Smuggling(HRS, Desync Attack)의…

