Impact
Contrast is a confidential‑computing runtime for Kubernetes. In Contrast versions prior to 1.19.1, the Kata agent policies generated by the Contrast CLI contain a flaw in the CopyFile verification step that permits arbitrary writes to the guest root filesystem. The flaw is a path‑traversal style problem (CWE‑59). An attacker can overwrite critical system files or otherwise manipulate the guest environment, effectively taking full control of the workload or causing it to leak sensitive data.
Affected Systems
The affected product is Edgeless Systems’ Contrast runtime. All releases before 1.19.1 are vulnerable. The vulnerability exists in the Kata agent policy component bundled with the Contrast CLI. No specific versions beyond that are listed as affected.
Risk and Exploitability
The CVSS base score of 8.6 indicates a high‑severity vulnerability. The EPSS score is not available, making it hard to gauge how often attackers target this issue, but the vulnerability is not listed in the CISA KEV catalog. The attack requires a malicious process on an untrusted host that can connect to the Kata agent via its VSOCK interface. With that access, the attacker can issue a series of CopyFile requests to overwrite critical guest files or trick the workload into revealing confidential data. Because the bug allows arbitrary file overwrite, the impact is basically a full guest takeover should the host already bypass basic isolation.
OpenCVE Enrichment