Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Local Path Provisioner v0.0.36

Latest

Choose a tag to compare

@derekbit derekbit released this 08 May 17:18
Immutable release. Only release title and notes can be modified.

Security Fixes

  • Fixed HelperPod Template Injection, a high-severity HelperPod template injection vulnerability. A user with permission to edit the local-path-config ConfigMap could manipulate helperPod.yaml and cause the provisioner to create unsafe HelperPods during PVC provisioning or cleanup operations. This release adds HelperPod template validation to reject unsafe security-sensitive fields such as privileged containers, hostPath volumes, and dangerous pod security settings.

What's Changed

New Contributors

Full Changelog: v0.0.35...v0.0.36