CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
References
Link | Resource |
---|---|
https://github.com/cubefs/cubefs/issues/1882 | Issue Tracking Mitigation Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-12T00:00:00
Updated: 2023-04-12T00:00:00
Reserved: 2023-04-12T00:00:00
Link: CVE-2023-30512
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-12T06:15:07.580
Modified: 2023-05-15T19:26:44.667
Link: CVE-2023-30512
JSON object: View
Redhat Information
No data.
CWE