| - module: sigs.k8s.io/secrets-store-csi-driver |
| - package: sigs.k8s.io/secrets-store-csi-driver/controllers |
| - SecretProviderClassPodStatusReconciler.Reconcile |
| - package: sigs.k8s.io/secrets-store-csi-driver/pkg/rotation |
| - package: sigs.k8s.io/secrets-store-csi-driver/pkg/secrets-store |
| - nodeServer.NodeUnpublishVolume |
| summary: Directory traversal in sigs.k8s.io/secrets-store-csi-driver |
| Modifying pod status allows host directory traversal. |
| Kubernetes Secrets Store CSI Driver allows an attacker who can modify a |
| SecretProviderClassPodStatus/Status resource the ability to write content to the |
| host filesystem and sync file contents to Kubernetes Secrets. This includes |
| paths under var/lib/kubelet/pods that contain other Kubernetes Secrets. |
| published: 2022-02-15T01:57:18Z |
| - fix: https://github.com/kubernetes-sigs/secrets-store-csi-driver/pull/371 |
| - fix: https://github.com/kubernetes-sigs/secrets-store-csi-driver/commit/c2cbb19e2eef16638fa0523383788a4bc22231fd |