VYPR

apk package

chainguard/vault-csi-provider

pkg:apk/chainguard/vault-csi-provider

Vulnerabilities (82)

  • CVE-2020-8567MedJan 21, 2021
    affected < 0fixed 0

    Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/l

  • CVE-2020-8559MedJul 22, 2020
    affected < 1.6.0-r2fixed 1.6.0-r2

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Page 5 of 5