CVE-2025-71424
Last modified
CVE-2025-71424 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent.
Description
Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent. As a result, on bare-metal Contrast deployments (AKS deployments are not affected) that run an image declaring at least one VOLUME for which no Kubernetes mount exists at that path, the untrusted host can write arbitrary file trees below that mount point inside the confidential container, compromising the integrity of a directory that is typically important to the application's core functionality. Version 1.9.1 fixes the issue by disallowing this configuration in `contrast generate`.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| edgelesssys | contrast | < 1.9.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-71424?
How severe is CVE-2025-71424?
How do I fix CVE-2025-71424?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71419UVdesk core-framework before 1.1.7 contains a stored cross-s…5.4
- CVE-2025-7142A vulnerability, which was classified as problematic, has be…5.4
- CVE-2025-71420UVdesk core-framework before 1.1.7 contains an authorization…4.3
- CVE-2025-71421UVdesk core-framework before 1.1.7 contains an improper priv…7.2
- CVE-2025-71422Contrast is a Kubernetes runtime for confidential containers…5.7
- CVE-2025-71423Edgelesssys Contrast is a confidential-computing runtime for…7.3
- CVE-2025-71425Contrast (Edgeless Systems) before 1.8.1 logs the workload s…7.3
- CVE-2025-71426Contrast is a confidential-computing runtime for Kubernetes.…7.1
- CVE-2025-7143A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-7144A vulnerability has been found in SourceCodester Best Salon …4.8
- CVE-2025-7145ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Co…8.6
- CVE-2025-7146The iPublish System developed by Jhenggao has an Arbitrary F…8.7
Are you affected by CVE-2025-71424?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
