MEDIUM4.9
GHSA-2v35-wj4r-rcmv
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
Quick fix
GHSA-2v35-wj4r-rcmv — github.com/hashicorp/vault-csi-provider: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault-csi-provider@v0.0.6Details
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including `/var/lib/kubelet/pods`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault-csi-provider
Introduced in:
0Fixed in: 0.0.6Fix
go get github.com/hashicorp/vault-csi-provider@v0.0.6Go/github.com/Azure/secrets-store-csi-driver-provider-azure
Introduced in:
0Fixed in: 0.0.10Fix
go get github.com/Azure/secrets-store-csi-driver-provider-azure@v0.0.10Go/github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
Introduced in:
0Fixed in: 0.2.0Fix
go get github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp@v0.2.0References
- https://nvd.nist.gov/vuln/detail/CVE-2020-8567[ADVISORY]
- https://github.com/kubernetes-sigs/secrets-store-csi-driver/issues/384[WEB]
- https://github.com/Azure/secrets-store-csi-driver-provider-azure/pull/298[WEB]
- https://github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp/pull/74[WEB]
- https://github.com/hashicorp/secrets-store-csi-driver-provider-vault/pull/50[WEB]
- https://groups.google.com/g/kubernetes-secrets-store-csi-driver/c/BI2qisiNXHY[WEB]