漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kubernetes Secrets Store CSI Driver plugin directory traversals
Vulnerability Description
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
Vulnerability Type
路径遍历:’../filedir’
Vulnerability Title
Kubernetes SIGs Secrets-store-csi-driver 路径遍历漏洞
Vulnerability Description
Kubernetes SIGs Secrets-store-csi-driver是Kubernetes SIGs组织的一个基于CSI卷用于存储机密文件的K8s组件。 Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6 存在安全漏洞,攻击者可利用该漏洞创建特殊制作的SecretProviderClass对象来写入主机文件系统上的任意文件路径。
CVSS Information
N/A
Vulnerability Type
N/A