Kubernetes Pod Escape Using Log Mounts
ID: 7eb7aacf-1185-5174-af8f-a36e60c1fc89
STIX ID: report--7eb7aacf-1185-5174-af8f-a36e60c1fc89
Feed Name: Aqua Security Blog
This report demonstrates a Kubernetes pod escape technique: a root container with a writable hostPath mount to /var/log can create symlinks that the kubelet follows, allowing an attacker to read arbitrary host files (for example /etc/shadow) and potentially obtain credentials or escalate to root on the node; the author provides a proof-of-concept, links to code, explains the mechanism, and recommends mitigations such as avoiding root containers and blocking writable /var/log hostPath mounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
