A security vulnerability was discovered in Kubernetes that could allow a user with the ability to create a pod and associate a gitRepo volume to execute arbitrary commands beyond the container boundary. This vulnerability leverages the hooks folder in the target repository to run arbitrary commands outside of the container's boundary.
Unversioned Kubernetes is available via kubernetes-1.29.11 in F40 and F41. Versioned Kubernetes is available via kubernetes1.29-1.29.11, kubernetes1.30-1.30.7, kubernetes1.31-1.31.1, and kubernetes1.32-1.32.0. Vulnerable versions are (https://www.cve.org/CVERecord?id=CVE-2024-10220): affected affected from 0 through 1.28.11 affected from 1.29.0 through 1.29.6 affected from 1.30.0 through 1.30.2 unaffected unaffected at 1.31.0 All current versions of Fedora kubernetes rpms are fixed or not affected.