The Kubernetes ecosystem is dealing with a new security flaw that if breached could allow an attacker to use an infected container to replace or create new files on a user’s workstation. The flaw is the latest in a string of security issues that have cropped up across the space.
The most recent flaw, which was discovered by Charles Holmes from Atredis Partners, is in the Kubernetes kubectl command-line tool. This tool is what allows running commands against a Kubernetes cluster to deploy applications, inspect and manage cluster resources, and view logs.
In a message post, Joel Smith, who works with the Kubernetes Product Security Committee, described the bug as “high severity and upgrading kubectl to Kubernetes 1.12.9, 1.13.6, and 1.14.2 or later is encouraged to fix this issue.”
Smith added that the latest vulnerability was similar to the CVE-2019-1002101 bug found earlier this year. That issue was discovered by Twistlock security researcher Ariel Zelivansky and also deemed high severity.
Most major Kubernetes distros sent out updates to their managed platforms to fix that flaw, however it appears that the initial fix was not enough. “The original fix for that issue was incomplete and a new exploit method was discovered,” Smith wrote.
That previous flaw itself was linked to a patch that was sent out last year.
Kubernetes Security ChallengeThe latest bug was announced just a day after the Kubernetes community released its latest platform update. The 1.15 iteration included 25 “enhancements” with the main updates focusing on stability of core feature sets and greater extensibility.
However, security remains a sticky issue.
Aaron Crickenberger, release lead for the Kubernetes 1.14 update from earlier this year, noted in an email to SDxCentral that the Kubernetes community does not view security as something tied to specific updates and instead is “something to be continually evaluated and improved.”
“There were numerous bug fixes and security fixes included in [the 1.14] release – as with any Kubernetes release – but few were as visible to people (or succinctly describable)" as a role-based access control (RBAC) change that was part of the 1.14 release, Crickenberger explained. He did add that deeper work was ongoing through the Security Audit Working Group that was established last year.
The Kubernetes 1.13 release last December was marred by the discovery of a “critical” flaw that gave hackers full administrative privileges on any compute node being run in a Kubernetes cluster. The flaw, which was discovered by a software engineer at Rancher Labs, garnered a 9.8 (critical) score out of 10 on the Common Vulnerability Scoring System (CVSS).
Security firms have noted that the discovery of security flaws it to be expected, and that it’s likely to continue. Rani Osnat, vice president of product marketing at Aqua Security, succinctly noted that Kubernetes is a “complex system and it’s bound to have vulnerabilities. The fact that CVE disclosures are becoming more commonplace is a good thing, as is the fact that they’re not all severe.”
Comments