GHSA-93xx-cvmc-9w3v
MEDIUMCVE-2023-30840If a malicious user gains control of a Kubernetes node running fluid csi pod (controlled by the csi-nodeplugin-fluid node-daemonset), he/she can leverage the fluid-csi service account to modify specs of all the nodes in the cluster. However, since this service account lacks "list node" permissions, the attacker may need to use other techniques to identify vulnerable nodes.
- Affected
- >=0.7.0, <0.8.6
- Fixed in
- 0.8.6
- Published
- 2023-05-09
- Source
- github