Hacker News new | ask | show | jobs
by lsandler 1735 days ago
while "official" hostPath feature is intended to provide the same result, it is being watched by practically all security and compliance tools, so such access can't go unnoticed. With the subPath abuse attackers can obtain complete host file system access undetected. So it is really urgent to start scanning for this vulnerability and potential exploits until your Kubernetes version is upgraded.