Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in the Fission serverless framework, affecting deployments on Kubernetes. If exploited, it could allow unauthorized access to sensitive host system resources, potentially leading to a compromise of the entire node or cluster. The main concern is confirming relevance and exposure.
- Allows privileged container escape.
- Impacts Kubernetes cluster security.
- Assess Fission framework exposure.
Attack Path
How an attacker could exploit the issue
An attacker with existing access to a Kubernetes cluster and the ability to create or update environments within Fission could potentially run privileged containers. These containers, scheduled with elevated permissions by Fission's executor, could break out of their sandbox, gaining access to the host system's files and network, and potentially compromising the entire node or cluster.
- Authenticated tenant with specific RBAC.
- Running a privileged container.
- Potential for node and cluster compromise.
Live Threat
Current exploitation, exposure, and threat context
A tenant with specific Kubernetes RBAC permissions could run privileged containers within the Fission function or builder namespace. This could allow these containers to escape their sandbox, potentially gaining access to the host filesystem and network, which could lead to node or cluster-level compromise when supported by the advisory.
- Cluster node and network access.
- Container sandbox escape.
- Potential cluster compromise.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
Security and Platform Engineering teams are likely responsible for addressing this vulnerability, given its impact on the Kubernetes-native Fission framework. The first practical step involves identifying all Fission deployments within your environment, confirming their exposure and criticality, and then coordinating with the accountable application or platform owners to plan remediation, which may involve vendor coordination or careful maintenance window planning.
- Platform and Security teams should own.
- Verify Fission deployment reachability and criticality.
- Plan coordinated remediation actions.