CVE-2023-30512: Medium severity linux foundation cubefs vulnerability
Published Apr 12, 2023
·Updated
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
Affected Software
1 affected component
linuxfoundation Cubefs<=3.2.1
Event History
Apr 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-30512?
CVE-2023-30512 is rated as high severity due to its potential for Kubernetes cluster-level privilege escalation.
2
How do I fix CVE-2023-30512?
To fix CVE-2023-30512, upgrade CubeFS to version 3.2.2 or later where the privileged access has been addressed.
3
What type of vulnerability is CVE-2023-30512?
CVE-2023-30512 is a privilege escalation vulnerability affecting Kubernetes clusters using CubeFS.
4
Who is affected by CVE-2023-30512?
Users running CubeFS versions up to 3.2.1 in Kubernetes environments are at risk from CVE-2023-30512.
5
What components are involved in CVE-2023-30512?
The vulnerability involves the DaemonSet component featuring the cfs-csi-cluster-role that allows secret listing.