目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-71424— Edgeless Systems Contrast 1.9.1 之前版本不安全的卷挂载漏洞

一分钟漏洞结论

影响对象
edgelesssys contrast
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Contrast 是 Edgeless Systems 提供的用于 Kubernetes 上机密容器的运行时系统。在 1.9.0 及更早版本中,Contrast 受到以下漏洞的影响: Dockerfile 中的 指令(对应 OCI 镜像配置中的 )仅作为提示,并不被 Kubernetes 特别处理。然而,当 Kubernetes 未指定挂载点时,containerd 会为其添加一个挂载点,这要求运行时系统能够将任意数据推送到 Kata Agent。因此,在未受影响的 AKS 部署之外,基于裸机部署的 Contras

CVSS 3.5 · Low EPSS 0.16% · P5
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-71424 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount
来源: CVE Program / CVE List V5
Vulnerability Description
Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent. As a result, on bare-metal Contrast deployments (AKS deployments are not affected) that run an image declaring at least one VOLUME for which no Kubernetes mount exists at that path, the untrusted host can write arbitrary file trees below that mount point inside the confidential container, compromising the integrity of a directory that is typically important to the application's core functionality. Version 1.9.1 fixes the issue by disallowing this configuration in `contrast generate`.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
edgelesssys contrast 0 ~ 1.9.1 -

二、漏洞 CVE-2025-71424 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-71424 的情报信息

请登录查看更多情报信息。

CVE-2025-71424 厂商安全公告 (1)

CVE-2025-71424 其他参考 (1)

同批安全公告 · edgelesssys · 2026-09-27 · 共 11 条

CVE-2026-100839 8.4 HIGH Contrast 1.18.0 前 AML注入导致远程代码执行漏洞
CVE-2026-100833 8.2 HIGH Contrast 1.23.1 以下镜像替换策略生成漏洞
CVE-2026-100838 8.1 HIGH Contrast 1.19.1以下 CopyFile策略符号链接漏洞
CVE-2026-100835 7.4 HIGH Contrast 1.16.0 之前远程证明中继攻击漏洞
CVE-2025-71425 7.3 HIGH Contrast 1.8.1之前日志记录信息泄露漏洞
CVE-2025-71423 7.3 HIGH Edgelessys Contrast 1.12.2 前工作负载密钥信息泄露漏洞
CVE-2025-71426 7.1 HIGH Contrast 1.4.1 协调器未认证恢复导致的模拟漏洞
CVE-2025-71422 5.7 MEDIUM Contrast 1.12.1 LUKS2持久存储漏洞
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast 1.20.0 拒绝服务漏洞
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast 1.20.0 凭据泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-71424

暂无评论


发表评论