PT-2026-80731 · Velero · Velero
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Velero versions prior to 1.18.1
Description
An attacker who gains control of the backup object-storage backend can upload a malicious backup tarball. This tarball can contain parent-directory paths that allow files to escape the intended extraction directory during the restore process, enabling the overwriting of sensitive files within the Velero pod filesystem.
Recommendations
Update to version 1.18.1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velero