Description
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2051 | Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods. |
Github GHSA |
GHSA-2v35-wj4r-rcmv | Kubernetes Secrets Store CSI Driver plugins arbitrary file write |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T18:23:40.732Z
Reserved: 2020-02-03T00:00:00.000Z
Link: CVE-2020-8567
No data.
Status : Modified
Published: 2021-01-21T17:15:14.063
Modified: 2024-11-21T05:39:02.770
Link: CVE-2020-8567
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA