Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories
ID: 071999dc-be87-51fc-a322-9311cec35796
STIX ID: report--071999dc-be87-51fc-a322-9311cec35796
Feed Name: cybersecurityNews.com
Threat Score
A path traversal vulnerability in the Kubernetes CSI Driver for NFS (nfs.csi.k8s.io) allows attackers who can create PersistentVolumes to include "../" sequences in the subDir/volumeHandle, which may cause the CSI controller to modify or delete directories outside the intended NFS export; all versions prior to v4.13.1 are affected and the recommended remediation is to upgrade to v4.13.1 or later and limit PV creation to trusted users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
