Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cgx-vhfp-6cf9

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Directory traversal in Kubernetes Secrets Store CSI Driver

Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.

Specific Go Packages Affected

sigs.k8s.io/secrets-store-csi-driver/controllers sigs.k8s.io/secrets-store-csi-driver/pkg/rotation sigs.k8s.io/secrets-store-csi-driver/pkg/secrets-store

Пакеты

Наименование

sigs.k8s.io/secrets-store-csi-driver

go
Затронутые версииВерсия исправления

>= 0.0.15, < 0.0.17

0.0.17

EPSS

Процентиль: 63%
0.00449
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-22
CWE-24

Связанные уязвимости

CVSS3: 5.8
nvd
около 5 лет назад

Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.

EPSS

Процентиль: 63%
0.00449
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-22
CWE-24