First published: Thu Jan 21 2021(Updated: )
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
Credit: jordan@liggitt.net jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Google Secret Manager Provider For Secret Store Csi Driver | <0.2.0 | |
Hashicorp Vault Provider For Secrets Store Csi Driver | <0.0.6 | |
Microsoft Azure Key Vault Provider For Secrets Store Csi Driver | <0.0.10 | |
go/github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp | <0.2.0 | 0.2.0 |
go/github.com/Azure/secrets-store-csi-driver-provider-azure | <0.0.10 | 0.0.10 |
go/github.com/hashicorp/vault-csi-provider | <0.0.6 | 0.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.