How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Security Advisories for Longhorn CVE-2021-36779 & CVE-2021-36780

calendar_today December 17, 2021 person domain longhorn

Overview There are two vulnerabilities found in released versions (< 1.1.3, < 1.2.3) as below. They have been fixed in the latest releases (1.1.3, 1.2.3). For more details, see each issue and security advisories. CVE-2021-36779: Host operations allowed in privileged Longhorn managed pods CVE-2021-36780: Unauthorized data access from replicas through vulnerable instance manager pods CVE-2021-36779: Host operations allowed in privileged Longhorn managed pods The privileged pods are managed by Longhorn running on every node for volume replica management in a Kubernetes cluster.

open_in_new Read original post