ack-fluid is the data cache acceleration component for the cloud-native AI suite. A security vulnerability affects ack-fluid component versions v1.0.6 and earlier. In an affected cluster, an attacker with permissions to create and modify Dataset and JuiceFSRuntime resources can maliciously modify a CustomResourceDefinition. This can lead to script injection and subsequent privilege escalation on a node. To improve security, we recommend that you upgrade the ack-fluid component to version v1.0.7 or later.
Scope of impact
This vulnerability affects clusters that run ack-fluid component version v1.0.6 or earlier and use JuiceFSRuntime. To resolve this issue, upgrade the ack-fluid component as soon as possible.
This issue is fixed in ack-fluid component versions v1.0.7 and later, which do not require an upgrade.
Check and upgrade the component
You can check and upgrade the ack-fluid component by using one of the following two methods. We recommend upgrading the component through the cloud-native AI suite for a one-click upgrade that requires no configuration.
(Recommended) Cloud-native AI suite
Log on to the ACK console. In the left navigation pane, click Clusters.
On the Clusters page, click the name of your cluster. In the left navigation pane, click .
-
On the cloud-native AI suite page, find the ack-fluid component in the Components list, and then click Upgrade in the Actions column.
If the Upgrade button is not displayed, the component is already up to date.
-
In the Upgrade Component dialog box, click OK.
App Catalog
Log on to the ACK console. In the left navigation pane, click Clusters.
On the Clusters page, click the name of your cluster. In the left navigation pane, click .
-
In the Helm list, find the ack-fluid component and check its version in the Chart Version column. If the component version is earlier than 1.0.7, click Update in the Actions column.
-
On the Update Release page, confirm that the component version is 1.0.7 or later, and then click OK.
References
For more information about the core features and key concepts of Fluid data acceleration, see elastic dataset.