diff --git a/advisories/github-reviewed/2022/05/GHSA-2v35-wj4r-rcmv/GHSA-2v35-wj4r-rcmv.json b/advisories/github-reviewed/2022/05/GHSA-2v35-wj4r-rcmv/GHSA-2v35-wj4r-rcmv.json index 43ea955bdcc..9952e8b903a 100644 --- a/advisories/github-reviewed/2022/05/GHSA-2v35-wj4r-rcmv/GHSA-2v35-wj4r-rcmv.json +++ b/advisories/github-reviewed/2022/05/GHSA-2v35-wj4r-rcmv/GHSA-2v35-wj4r-rcmv.json @@ -1,17 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-2v35-wj4r-rcmv", - "modified": "2024-04-24T20:07:30Z", + "modified": "2024-07-08T20:40:04Z", "published": "2022-05-24T17:40:02Z", "aliases": [ "CVE-2020-8567" ], "summary": "Kubernetes Secrets Store CSI Driver plugins arbitrary file write", - "details": "Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.", + "details": "Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including `/var/lib/kubelet/pods`.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L" } ], "affected": [