Vulnerability Report: GO-2024-2750
- CVE-2020-8567, GHSA-2v35-wj4r-rcmv
- Affects: github.com/Azure/secrets-store-csi-driver-provider-azure, github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp, and 1 more
- Published: Jun 05, 2024
- Modified: Sep 06, 2024
- Unreviewed
Kubernetes Secrets Store CSI Driver plugins arbitrary file write in github.com/Azure/secrets-store-csi-driver-provider-azure. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/Azure/secrets-store-csi-driver-provider-azure before v0.0.10; github.com/hashicorp/vault-csi-provider before v0.0.6.
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-2v35-wj4r-rcmv or https://nvd.nist.gov/vuln/detail/CVE-2020-8567.
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixedbefore 0.0.10
-
before v0.2.0-
-
all versions, no known fixedbefore 0.0.6
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck
. (See this note on versions for more details.)
Aliases
References
- https://github.com/advisories/GHSA-2v35-wj4r-rcmv
- https://nvd.nist.gov/vuln/detail/CVE-2020-8567
- https://github.com/Azure/secrets-store-csi-driver-provider-azure/pull/298
- https://github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp/pull/74
- https://github.com/hashicorp/secrets-store-csi-driver-provider-vault/pull/50
- https://github.com/kubernetes-sigs/secrets-store-csi-driver/issues/384
- https://groups.google.com/g/kubernetes-secrets-store-csi-driver/c/BI2qisiNXHY
- https://vuln.go.dev/ID/GO-2024-2750.json