CVE-2020-8567
MEDIUMGoogle Secret Manager Provider For Secret Store Csi Driver < 0.2.0 - Path Traversal
Title source: ruleDescription
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
Scores
CVSS v3
4.9
EPSS
0.0015
EPSS Percentile
36.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
Classification
CWE
CWE-22
CWE-24
Status
published
Affected Products (6)
google/secret_manager_provider_for_secret_store_csi_driver
< 0.2.0
hashicorp/vault_provider_for_secrets_store_csi_driver
< 0.0.6
microsoft/azure_key_vault_provider_for_secrets_store_csi_driver
< 0.0.10
hashicorp/vault-csi-provider
< 0.0.6Go
Azure/secrets-store-csi-driver-provider-azure
< 0.0.10Go
GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
< 0.2.0Go
Timeline
Published
Jan 21, 2021
Tracked Since
Feb 18, 2026