Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40828
HistoryJun 08, 2023 - 2:59 a.m.

Insertion Of Sensitive Information Into Log File

2023-06-0802:59:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
k8s.io secrets-store-csi-driver
vulnerability
sensitive information
log file

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS

0

Percentile

15.5%

sigs.k8s.io/secrets-store-csi-driver is vulnerable to Insertion of Sensitive Information Into Log File. An attacker with access to the driver logs could observe service account tokens due to the NodePublishVolume function of nodeserver.go

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS

0

Percentile

15.5%