blob: de710d9b033385c012d733b3f2cf128df141873b [file] [log] [blame]
id: GO-2023-1763
modules:
- module: github.com/fluid-cloudnative/fluid
versions:
- introduced: 0.7.0
- fixed: 0.8.6
vulnerable_at: 0.8.5
summary: |-
On a compromised node, the fluid-csi service account can be used to modify node
specs in github.com/fluid-cloudnative/fluid
cves:
- CVE-2023-30840
ghsas:
- GHSA-93xx-cvmc-9w3v
references:
- advisory: https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-93xx-cvmc-9w3v
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-30840
- fix: https://github.com/fluid-cloudnative/fluid/commit/77c8110a3d1ec077ae2bce6bd88d296505db1550
- fix: https://github.com/fluid-cloudnative/fluid/commit/91c05c32db131997b5ca065e869c9918a125c149
- web: https://github.com/fluid-cloudnative/fluid/releases/tag/v0.8.6
source:
id: GHSA-93xx-cvmc-9w3v
created: 2024-08-20T11:43:28.797374-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE