Description
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0837 | Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets. |
Github GHSA |
GHSA-5cgx-vhfp-6cf9 | Directory traversal in Kubernetes Secrets Store CSI Driver |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-17T03:28:40.493Z
Reserved: 2020-02-03T00:00:00.000Z
Link: CVE-2020-8568
No data.
Status : Modified
Published: 2021-01-21T17:15:14.157
Modified: 2024-11-21T05:39:02.890
Link: CVE-2020-8568
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA