VDB
Sign up
MEDIUM4.9

GHSA-2v35-wj4r-rcmv

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

Quick fix

GHSA-2v35-wj4r-rcmv — github.com/hashicorp/vault-csi-provider: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault-csi-provider@v0.0.6

Details

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including `/var/lib/kubelet/pods`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault-csi-provider
Introduced in: 0Fixed in: 0.0.6
Fixgo get github.com/hashicorp/vault-csi-provider@v0.0.6
Go/github.com/Azure/secrets-store-csi-driver-provider-azure
Introduced in: 0Fixed in: 0.0.10
Fixgo get github.com/Azure/secrets-store-csi-driver-provider-azure@v0.0.10
Go/github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
Introduced in: 0Fixed in: 0.2.0
Fixgo get github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp@v0.2.0

References