漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
Vulnerability Description
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:P
Vulnerability Type
参数注入或修改
Vulnerability Title
Kata Containers 命令注入漏洞
Vulnerability Description
Kata Containers是Kata Containers组织开源的一款轻量级虚拟机构建程序。 Kata Containers 3.31.0之前版本存在命令注入漏洞,该漏洞源于默认配置允许通过`io.katacontainers.config.hypervisor.virtio_fs_extra_args`注释注入任意命令行参数,结合`kernel_params`注释激活调试控制台,导致攻击者可读取或写入主机上的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A