Vulnerabilities (CVE)

Filtered by vendor Linuxfoundation Subscribe
Filtered by product Cubefs
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30512 1 Linuxfoundation 1 Cubefs 2025-02-07 N/A 6.5 MEDIUM
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.