apk package
chainguard/vault-csi-provider
pkg:apk/chainguard/vault-csi-provider
Vulnerabilities (83)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-2878 | Med | 6.5 | < 1.4.0-r9 | 1.4.0-r9 | Jun 7, 2023 | Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs. | |
| CVE-2020-8567 | Med | 4.9 | < 0 | 0 | Jan 21, 2021 | Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/l | |
| CVE-2020-8559 | Med | 6.4 | < 1.6.0-r2 | 1.6.0-r2 | Jul 22, 2020 | The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. |
- affected < 1.4.0-r9fixed 1.4.0-r9
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
- affected < 0fixed 0
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/l
- affected < 1.6.0-r2fixed 1.6.0-r2
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Page 5 of 5