An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.
Related Articles
All Mix →OWASP Chicago 2018 – Pentesting with Serverless Infrastructure
Slides Supplemental Serverless Toolkit available here: https://github.com/ropnop/serverless_toolkit Source link
The Bimbo And The Caveman: Relationships vs. Nature
Have you ever noticed that the more intelligent a man is the less masculine he tends to be? And doesn’t it seem like the smarter…
Google Chrome Has Wicked Quick Searches
Table of Contents Above and Beyond Visual Searches Automatically Adding New Quicksearches One of the reasons people don’t want to leave Firefox for Google’s new…
Ramblings and a Tool · Joseph Thacker
Table of Contents One Big Component Two Main Arguments What this means Get started A few weeks ago I wrote about how AI is going…
Content Security Policy (CSP) explained including common bypasses
Table of Contents Example policy self inline eval Callback CDN – anyone can upload files CDN – abusing existing libraries Injection in the actual policy…
Mail.ru Group pays out over $1 million in bounties
“It’s not worth building a fence if it can be bypassed just two steps to the side” Mail.ru Group is a bug bounty veteran; with…

