Directory traversal in Kubernetes Secrets Store CSI Driver
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
>= 0.0.15, < 0.0.17
Patched versions
0.0.17
Description
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Oct 2, 2023
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a
SecretProviderClassPodStatus/Status
resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths undervar/lib/kubelet/pods
that contain other Kubernetes Secrets.Specific Go Packages Affected
sigs.k8s.io/secrets-store-csi-driver/controllers
sigs.k8s.io/secrets-store-csi-driver/pkg/rotation
sigs.k8s.io/secrets-store-csi-driver/pkg/secrets-store
References