Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
References
Link | Resource |
---|---|
https://github.com/kubernetes/kubernetes/issues/118419 | Exploit Issue Tracking |
https://groups.google.com/g/kubernetes-security-announce/c/5K8ghQHBDdQ/m/Udee6YUgAAAJ | Mailing List |
https://security.netapp.com/advisory/ntap-20230814-0003/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-06-07 15:15
Updated : 2023-10-02 17:08
NVD link : CVE-2023-2878
Mitre link : CVE-2023-2878
CVE.ORG link : CVE-2023-2878
JSON object : View
Products Affected
kubernetes
- secrets-store-csi-driver
CWE
CWE-532
Insertion of Sensitive Information into Log File