Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Kubernetes Subscribe
Filtered by product Secrets Store Csi Driver
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8568 1 Kubernetes 1 Secrets Store Csi Driver 2021-01-28 4.9 MEDIUM 6.5 MEDIUM
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.