Kubernetes Secrets Store CSI Driver sync/rotate directory traversal
CVE-2020-8568
5.8MEDIUM
Key Information:
- Vendor
Kubernetes
- Vendor
- CVE Published:
- 21 January 2021
What is CVE-2020-8568?
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kubernetes Secrets Store CSI Driver Kubernetes Secrets Store CSI Driver v0.0.15
Kubernetes Secrets Store CSI Driver Kubernetes Secrets Store CSI Driver v0.0.16