- Function Overview
- Product Bulletin
- Service Overview
- Billing
- Getting Started
-
User Guide
- Clusters
- Workloads
- Network
- Storage
- O&M
- Namespaces
- ConfigMaps and Secrets
- Auto Scaling
- Add-ons
- Helm Chart
- Permissions
- Settings
- Best Practices
-
API Reference
- Before You Start
- API Overview
- Calling APIs
-
APIs
- Autopilot Cluster Management
- Add-on Management for Autopilot Clusters
-
Autopilot Cluster Upgrade
- Upgrading a Cluster
- Obtaining Cluster Upgrade Task Details
- Retrying a Cluster Upgrade Task
- Obtaining a List of Cluster Upgrade Task Details
- Performing a Pre-upgrade Check for a Cluster
- Obtaining Details About a Pre-upgrade Check Task of a Cluster
- Obtaining a List of Pre-upgrade Check Tasks of a Cluster
- Performing a Post-upgrade Check for a Cluster
- Backing Up a Cluster
- Obtaining a List of Cluster Backup Task Details
- Obtaining the Cluster Upgrade Information
- Obtaining a Cluster Upgrade Path
- Obtaining the Configuration of Cluster Upgrade Feature Gates
- Enabling the Cluster Upgrade Process Booting Task
- Obtaining a List of Upgrade Workflows
- Obtaining Details About a Specified Cluster Upgrade Booting Task
- Updating the Status of a Specified Cluster Upgrade Booting Task
- Quota Management for Autopilot Clusters
- Tag Management for Autopilot Clusters
-
Chart Management for Autopilot Clusters
- Uploading a Chart
- Obtaining a Chart List
- Obtaining a Release List
- Creating a Release
- Updating a Chart
- Deleting a Chart
- Updating a Release
- Obtaining a Chart
- Deleting a Release
- Obtaining a Release
- Downloading a Chart
- Obtaining Chart Values
- Obtaining Historical Records of a Release
- Obtaining the Quota of a User Chart
- Kubernetes APIs
- Permissions and Supported Actions
- Appendix
-
FAQs
- Billing
- Workloads
- Network Management
-
Storage
- Can PVs of the EVS Type in a CCE Autopilot Cluster Be Restored After They Are Deleted or Expire?
- What Can I Do If a Storage Volume Fails to Be Created?
- Can CCE Autopilot PVCs Detect Underlying Storage Faults?
- How Can I Delete the Underlying Storage If It Remains After a Dynamically Created PVC is Deleted?
- Permissions
- General Reference
Copied.
Notice of Kubernetes Security Vulnerability (CVE-2024-10220)
The Kubernetes community recently discovered a security vulnerability (CVE-2024-10220). This vulnerability allows an attacker who has the necessary permissions to create pods associated with gitRepo volumes to run arbitrary commands outside the containers. The attacker can exploit the hooks directory in the target Git repository to escape the containers and execute malicious commands.
Description
Type |
CVE-ID |
Severity |
Discovered |
---|---|---|---|
Container escape |
High |
2024-11-22 |
Impact
The affected cluster versions are as follows:
- v1.27.0-r0-v1.27.8-r0
- v1.28.0-r0-v1.28.6-r0
Identification Method
Log in to the CCE console, click the name of the target cluster to access the cluster console, and check the cluster version on the Overview page.

- If the cluster version is not one of the versions mentioned above, then the vulnerability does not affect the cluster.
- If the cluster version falls within the affected range, you can use the following command to check if the vulnerability has been exploited in the cluster:
(This command will display a list of all gitRepo storage volumes that are mounted to pods. It will also clone the repository to the pod in the .git subdirectory.)
kubectl get pods --all-namespaces -o yaml | grep gitRepo -A 2
If the command output does not show any gitRepo configuration, it means that the cluster is not affected by the vulnerability.
Solution
- This vulnerability has been fixed for CCE Autopilot clusters. Upgrade the cluster to the version where the vulnerability has been fixed promptly. For clusters that have reached EOS, upgrade them to versions under maintenance.
- The gitRepo storage volumes are no longer supported. As a solution, the community recommends using the init containers to perform Git clone operations and then mount the directories to the pods. For details, see the example in GitHub.
Helpful Links
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot