Kubernetes SIGs Secrets-store-csi-driver是Kubernetes SIGs组织的一个基于CSI卷用于存储机密文件的K8s组件。 Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6 存在安全漏洞,攻击者可利用该漏洞创建特殊制作的SecretProviderClass对象来写入主机文件系统上的任意文件路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kubernetes | Kubernetes Secrets Store CSI Driver | Vault Plugin ~ v0.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-8554 | 6.3 MEDIUM | Kubernetes man in the middle using LoadBalancer or ExternalIPs |
| CVE-2020-8568 | 5.8 MEDIUM | Kubernetes Secrets Store CSI Driver sync/rotate directory traversal |
| CVE-2020-8569 | 4.3 MEDIUM | Kubernetes CSI snapshot-controller DoS |
| CVE-2020-8570 | Kubernetes Java client libraries unvalidated path traversal in Copy implementation |
No comments yet