VDB

CVE-2020-8567

CVE-2020-8567 PUBLISHED CVSS 4.900000095367432 MEDIUM

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.

EPSS 1.37% · 69.3th percentile

Risk Scores

CVSS 3.1
4.900000095367432
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L
EPSS Score
1.37%
69.3th percentile

Affected Products

VendorProductVersions
github.comGoogleCloudPlatform/secrets-store-csi-driver-provider-gcp0
googlesecret_manager_provider_for_secret_store_csi_driver0
KubernetesKubernetes Secrets Store CSI DriverVault Plugin, Azure Plugin, *
hashicorpvault_provider_for_secrets_store_csi_driver0
microsoftazure_key_vault_provider_for_secrets_store_csi_driver0
github.comhashicorp/vault-csi-provider0
github.comAzure/secrets-store-csi-driver-provider-azure0

Timeline

  • Jan 21, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›