MEDIUM · 4.9

CVE-2020-8567

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass o...

Vulnerability Description

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.

CVSS Score

4.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
GoogleSecret Manager Provider For Secret Store Csi Driver< 0.2.0
HashicorpVault Provider For Secrets Store Csi Driver< 0.0.6
MicrosoftAzure Key Vault Provider For Secrets Store Csi Driver< 0.0.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8567?

CVE-2020-8567 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass o...

How severe is CVE-2020-8567?

CVE-2020-8567 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8567?

Check the references section above for vendor advisories and patch information. Affected products include: Google Secret Manager Provider For Secret Store Csi Driver, Hashicorp Vault Provider For Secrets Store Csi Driver, Microsoft Azure Key Vault Provider For Secrets Store Csi Driver.