CVE-2021-25741
Scheduled Maintenance Report for ForePaaS
Postmortem

IMPORTANT: Some of the cloud providers will need additional update soon as they got a new fix version available.
For now, only Google is fully fixed.

Posted Sep 16, 2021 - 10:53 CEST

Completed
The scheduled maintenance has been completed.
Posted Sep 16, 2021 - 10:50 CEST
In progress
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Sep 16, 2021 - 07:59 CEST
Scheduled
A vulnerability was recently discovered in Kubernetes, described in CVE-2021-25741, where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. This is rated as a High severity vulnerability. All Kubernetes Engine clusters nodes are affected by this vulnerability, and we recommend that you upgrade to the latest patch version as soon as possible, as we detail below, to ensure your workloads remain secure.
Posted Sep 16, 2021 - 07:58 CEST
This scheduled maintenance affected: Microsoft Azure Clusters (Azure AKS - ForePaaS France), OVH Clusters (OVH - ForePaaS Graveline 7 (OKS)), and Google Cloud Clusters (GCE GKE - forepaas-europe-west1).