All Products
Search
Document Center

Container Service for Kubernetes:[Component Updates] Update ack-fluid

Last Updated:Jan 10, 2025

ack-fluid is a data cache acceleration component provided by the cloud-native AI suite. If your cluster uses ack-fluid 1.0.6 or earlier, attackers have permissions to create and modify Datasets and the JuiceFSRuntime. They can inject scripts into CustomResourceDefinitions (CRDs) to launch node privilege escalation. To enhance security, we recommend that you update ack-fluid to 1.0.7 or later.

Affected versions

Clusters that use ack-fluid 1.0.6 or earlier and use the JuicefsRuntime are affected. Update ack-fluid at the earliest opportunity to fix the vulnerability.

Note

This vulnerability is fixed in ack-fluid 1.0.7 and later. No update is needed.

View and update the component

You can use one of the following methods to view and update the ack-fluid component. We recommend that you update ack-fluid by using the cloud-native AI suite in the Container Service for Kubernetes (ACK) console. This method does require additional configuration.

(Recommended) Update ack-fluid by using the cloud-native AI suite

  1. Log on to the ACK console. In the left-side navigation pane, click Clusters.

  2. On the Clusters page, find the cluster that you want to manage and click its name. In the left-side pane, choose Applications > Cloud-native AI Suite.

  3. In the Components list of the cloud-native AI suite page, find ack-fluid and click Upgrade in the Actions column.

    If the Upgrade button is not displayed, the latest version of ack-fluid is installed.

  4. In the Upgrade message, click Confirm.

Update ack-fluid by using the App Catalog module

  1. Log on to the ACK console. In the left-side navigation pane, click Clusters.

  2. On the Clusters page, find the cluster that you want to manage and click its name. In the left-side navigation pane, choose Applications > Helm.

  3. In the Helm list, find ack-fluid. View the version of ack-fluid in the Chart Version column. If the version is earlier than 1.0.7, click Update in the Actions column.

  4. In the Update Release panel, confirm that the ack-fluid version is 1.0.7 or later and click OK.

References

For more information about the key features and terms used in Fluid, see Overview of Fluid.