3 ms·
The root cause was a chain of known exploits due to very out of date software: * RunC v1.0.0-rc2 was released on Oct. 1, 2016, and was vulnerable to at least t
by dlor 5y ago
The root cause was a chain of known exploits due to very out of date software:
* RunC v1.0.0-rc2 was released on Oct. 1, 2016, and was vulnerable to at least two container breakout CVEs.
* ACI was hosted on clusters running either Kubernetes v1.8.4, v1.9.10 or v1.10.9. These versions were released between November 2017 and October 2018 and are vulnerable to multiple publicly known vulnerabilities.
Running multitenant workloads in Kubernetes is notoriously difficult, and staying on top of patches is simply table-stakes.
- Arnavion 5y agoAnd the Bridge SSRF one appears to be because someone was constructing URLs via concatenating instead of using a URL serializer / encoder. Eg https://play.rust-lang.org/?version=stable&mode=debug&edition=2018&gist=0872cc32e50b024a4c6752f5bd6787f4 https://play.rust-lang.org/?version=stable&mode=debug&editio... - A serializer not only detects characters that are completely illegal, but also escapes characters that need escaping to be legal.
- pathseeker 5y agoIt's not difficult, it's reckless bordering on incompetence. The shared kernel is just way to much attack space and shared resources to make it tenable in the face of adversaries.
- raesene9 5y agoYep given the number of CVEs in Kubernetes, and to a lesser extent runc, (https://www.container-security.site/general_information/container_cve_list.html https://www.container-security.site/general_information/cont...) it's pretty surprising to see a major cloud service running versions this old.