logo

Kubernetes Pod Escape Using Log Mounts

ID: 7eb7aacf-1185-5174-af8f-a36e60c1fc89

STIX ID: report--7eb7aacf-1185-5174-af8f-a36e60c1fc89

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2019-08-01

Date Updated: 2026-04-26

...
...

This report demonstrates a Kubernetes pod escape technique: a root container with a writable hostPath mount to /var/log can create symlinks that the kubelet follows, allowing an attacker to read arbitrary host files (for example /etc/shadow) and potentially obtain credentials or escalate to root on the node; the author provides a proof-of-concept, links to code, explains the mechanism, and recommends mitigations such as avoiding root containers and blocking writable /var/log hostPath mounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.