Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.
| Software | From | Fixed in |
|---|---|---|
| kubernetes / kubernetes | 1.6.3-beta.1 | 1.6.3-beta.1.x |
| kubernetes / kubernetes | 1.6.4-beta.1 | 1.6.4-beta.1.x |
| kubernetes / kubernetes | 1.6.1-beta.0 | 1.6.1-beta.0.x |
| kubernetes / kubernetes | 1.6.2-beta.0 | 1.6.2-beta.0.x |
| kubernetes / kubernetes | 1.6.3-beta.0 | 1.6.3-beta.0.x |
| kubernetes / kubernetes | 1.6.4-beta.0 | 1.6.4-beta.0.x |
| kubernetes / kubernetes | 1.6.5-beta.0 | 1.6.5-beta.0.x |
| kubernetes / kubernetes | 1.6.1 | 1.6.1.x |
| kubernetes / kubernetes | 1.6.2 | 1.6.2.x |
| kubernetes / kubernetes | 1.6.3 | 1.6.3.x |
| kubernetes / kubernetes | 1.6.4 | 1.6.4.x |
| kubernetes / kubernetes | 1.6.5 | 1.6.5.x |
| kubernetes / kubernetes | 1.6.0-alpha.0 | 1.6.0-alpha.0.x |
| kubernetes / kubernetes | 1.6.0-alpha.1 | 1.6.0-alpha.1.x |
| kubernetes / kubernetes | 1.6.0-alpha.2 | 1.6.0-alpha.2.x |
| kubernetes / kubernetes | 1.6.0-alpha.3 | 1.6.0-alpha.3.x |
| kubernetes / kubernetes | 1.6.0-beta.0 | 1.6.0-beta.0.x |
| kubernetes / kubernetes | 1.6.0-beta.1 | 1.6.0-beta.1.x |
| kubernetes / kubernetes | 1.6.0-beta.2 | 1.6.0-beta.2.x |
| kubernetes / kubernetes | 1.6.0-beta.3 | 1.6.0-beta.3.x |
| kubernetes / kubernetes | 1.6.0-beta.4 | 1.6.0-beta.4.x |
| kubernetes / kubernetes | 1.6.0-rc.1 | 1.6.0-rc.1.x |
| kubernetes / kubernetes | 1.6.0 | 1.6.0.x |