Skip to content

Remove gitRepo volume type #125983

@vinayakankugoyal

Description

@vinayakankugoyal

What would you like to be added?

I'd like to remove gitRepo volume types. It's been deprecated for 6 years now and if a giant foot gun.

In a recent blog a researcher has exploited it to get remote code execution(RCE).

https://irsl.medium.com/sneaky-write-hook-git-clone-to-root-on-k8s-node-e38236205d54

Why is this needed?

To prevent folks from using a deprecated and dangerous volume type.

Metadata

Metadata

Assignees

Labels

area/securitykind/featureCategorizes issue or PR as related to a new feature.needs-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.priority/critical-urgentHighest priority. Must be actively worked on as someone's top priority right now.sig/securityCategorizes an issue or PR as relevant to SIG Security.sig/storageCategorizes an issue or PR as relevant to SIG Storage.

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions