Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kubernetes Secrets Store CSI Driver sync/rotate directory traversal
Vulnerability Description
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
路径遍历:’../filedir’
Vulnerability Title
Kubernetes SIGs Secrets-store-csi-driver 路径遍历漏洞
Vulnerability Description
Kubernetes SIGs Secrets-store-csi-driver是Kubernetes SIGs组织的一个基于CSI卷用于存储机密文件的K8s组件。 Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 存在安全漏洞,攻击者可利用该漏洞修改SecretProviderClassPodStatus状态资源,能够向主机文件系统写入内容。
CVSS Information
N/A
Vulnerability Type
N/A