All Products
Search
Document Center

Container Service for Kubernetes:[Component Updates] Update ack-fluid

Last Updated:Mar 25, 2024

ack-fluid is a data cache acceleration component provided by the cloud-native AI suite. If your cluster uses ack-fluid 1.0.6 or earlier, attackers have permissions to create and modify Datasets and the JuiceFSRuntime. They can inject scripts into CustomResourceDefinitions (CRDs) to launch node privilege escalation. To enhance security, we recommend that you update ack-fluid to 1.0.7 or later.

Affected versions

Clusters that use ack-fluid 1.0.6 or earlier and use the JuicefsRuntime are affected. Update ack-fluid at the earliest opportunity to fix the vulnerability.

Note

This vulnerability is fixed in ack-fluid 1.0.7 and later. No update is needed.

View and update the component

You can use one of the following methods to view and update the ack-fluid component. We recommend that you update ack-fluid by using the cloud-native AI suite in the Container Service for Kubernetes (ACK) console. This method does require additional configuration.

(Recommended) Update ack-fluid by using the cloud-native AI suite

  1. Log on to the ACK console and click Clusters in the left-side navigation pane.

  2. On the Clusters page, click the name of the cluster that you want to manage and choose Applications > Cloud-native AI Suite in the left-side navigation pane.

  3. In the Components list of the cloud-native AI suite page, find ack-fluid and click Upgrade in the Actions column.

    If the Upgrade button is not displayed, the latest version of ack-fluid is installed.

  4. In the Upgrade message, click Confirm.

Update ack-fluid by using the App Catalog module

  1. Log on to the ACK console and click Clusters in the left-side navigation pane.

  2. On the Clusters page, click the name of the cluster that you want to manage and choose Applications > Helm in the left-side navigation pane.

  3. In the Helm list, find ack-fluid. View the version of ack-fluid in the Chart Version column. If the version is earlier than 1.0.7, click Update in the Actions column.

  4. In the Update Release panel, confirm that the ack-fluid version is 1.0.7 or later and click OK.

References

For more information about the key features and terms used in Fluid, see Overview of Fluid.