CubeFS allows Kubernetes cluster-level privilege escalation
Moderate severity
GitHub Reviewed
Published
Apr 12, 2023
to the GitHub Advisory Database
•
Updated May 15, 2023
Description
Published by the National Vulnerability Database
Apr 12, 2023
Published to the GitHub Advisory Database
Apr 12, 2023
Reviewed
Apr 12, 2023
Last updated
May 15, 2023
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
References