Lucene search

K
cveKubernetesCVE-2020-8568
HistoryJan 21, 2021 - 5:15 p.m.

CVE-2020-8568

2021-01-2117:15:14
CWE-20
CWE-24
CWE-22
kubernetes
web.nvd.nist.gov
44
2
cve-2020-8568
kubernetes
secrets store csi driver
security vulnerability
kubernetes secrets
nvd

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

37.3%

Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.

Affected configurations

Nvd
Node
kubernetessecrets_store_csi_driverMatch0.0.15
OR
kubernetessecrets_store_csi_driverMatch0.0.16
VendorProductVersionCPE
kubernetessecrets_store_csi_driver0.0.15cpe:2.3:a:kubernetes:secrets_store_csi_driver:0.0.15:*:*:*:*:*:*:*
kubernetessecrets_store_csi_driver0.0.16cpe:2.3:a:kubernetes:secrets_store_csi_driver:0.0.16:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Kubernetes Secrets Store CSI Driver",
    "vendor": "Kubernetes",
    "versions": [
      {
        "status": "affected",
        "version": "Kubernetes Secrets Store CSI Driver v0.0.15"
      },
      {
        "status": "affected",
        "version": "Kubernetes Secrets Store CSI Driver v0.0.16"
      }
    ]
  }
]

Social References

More

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

37.3%