—
GO-2023-1763
On a compromised node, the fluid-csi service account can be used to modify node specs in github.com/fluid-cloudnative/fluid
Quick fix
GO-2023-1763 — github.com/fluid-cloudnative/fluid: upgrade to the fixed version with the command below.
go get github.com/fluid-cloudnative/fluid@v0.8.6Details
On a compromised node, the fluid-csi service account can be used to modify node specs in github.com/fluid-cloudnative/fluid
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/fluid-cloudnative/fluid
Introduced in:
0.7.0Fixed in: 0.8.6Fix
go get github.com/fluid-cloudnative/fluid@v0.8.6References
- https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-93xx-cvmc-9w3v[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-30840[ADVISORY]
- https://github.com/fluid-cloudnative/fluid/commit/77c8110a3d1ec077ae2bce6bd88d296505db1550[FIX]
- https://github.com/fluid-cloudnative/fluid/commit/91c05c32db131997b5ca065e869c9918a125c149[FIX]
- https://github.com/fluid-cloudnative/fluid/releases/tag/v0.8.6[WEB]