CyberRota Analysis
AI-GeneratedKubernetes deployments using Velero versions prior to 1.18.1 are vulnerable to an attack where a compromised backup object-storage backend can be exploited to upload a malicious backup tarball. This tarball can contain parent-directory paths that escape the extraction directory, potentially overwriting sensitive files within the Velero pod filesystem. Organizations utilizing Velero for backup and restore operations should prioritize upgrading to version 1.18.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwrite sensitive files in the Velero pod filesystem. This issue is fixed in version 1.18.1.