IT

Tracker / CVE-2020-8567

CVE-2020-8567

Medium 4.9

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.

Affected products and versions

google secret_manager_provider_for_secret_store_csi_driver · … → 0.2.0
hashicorp vault_provider_for_secrets_store_csi_driver · … → 0.0.6
microsoft azure_key_vault_provider_for_secrets_store_csi_driver · … → 0.0.10

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References