VDB
CVE-2024-3744
CVE-2024-3744
PUBLISHED
CVSS 6.5 MEDIUM
azure-file-csi-driver leaks service account tokens in the logs
EPSS 0.27% · 19.1th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
0.27%
19.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sigs.k8s.io | azurefile-csi-driver | 1.30.0, 0, 1.30.0 |
| Kubernetes | azure-file-csi-driver | v1.30.0, 1.29.3, v1.29.3 |
Timeline
- May 15, 2024 CVE Published
- May 15, 2024 EPSS Score
- Jun 8, 2024 EPSS Score
- Jul 2, 2024 EPSS Score
- Jul 27, 2024 EPSS Score
- Aug 20, 2024 EPSS Score
- Sep 13, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 7, 2024 EPSS Score
- Nov 1, 2024 EPSS Score
- Nov 25, 2024 EPSS Score
- Dec 20, 2024 EPSS Score
References
- https://groups.google.com/g/kubernetes-security-announce/c/hcgZE2MQo1A/m/Y4C6q-CYAgAJ mailing-list
- http://www.openwall.com/lists/oss-security/2024/05/09/4 url
- https://github.com/kubernetes-sigs/azurefile-csi-driver package
- https://github.com/kubernetes/kubernetes/issues/124759 discussion
- https://github.com/kubernetes-sigs/azurefile-csi-driver/commit/a1b7446de942136419f07394efeef804523f87ae fix
- https://github.com/kubernetes-sigs/azurefile-csi-driver/commit/e11ff3dc2c03894cde692213308f9991e7bbd5bf fix
- https://nvd.nist.gov/vuln/detail/CVE-2024-3744 advisory