Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-2C658A03934822BB90AFE4E99C4744D9
HistoryFeb 15, 2022 - 12:00 a.m.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

2022-02-1500:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
9
kubernetes
secrets store
csi driver
path traversal
attack
host filesystem
sync
kubernetes secrets

EPSS

0.001

Percentile

37.3%

Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.

EPSS

0.001

Percentile

37.3%

Related for GITLAB-2C658A03934822BB90AFE4E99C4744D9