Kubernetes SIGs Secrets-store-csi-driver是Kubernetes SIGs组织的一个基于CSI卷用于存储机密文件的K8s组件。 Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 存在安全漏洞,攻击者可利用该漏洞修改SecretProviderClassPodStatus状态资源,能够向主机文件系统写入内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kubernetes | Kubernetes Secrets Store CSI Driver | Kubernetes Secrets Store CSI Driver v0.0.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-8554 | 6.3 MEDIUM | Kubernetes man in the middle using LoadBalancer or ExternalIPs |
| CVE-2020-8567 | 4.9 MEDIUM | Kubernetes Secrets Store CSI Driver plugin directory traversals |
| CVE-2020-8569 | 4.3 MEDIUM | Kubernetes CSI snapshot-controller DoS |
| CVE-2020-8570 | Kubernetes Java client libraries unvalidated path traversal in Copy implementation |
No comments yet