Database/Container, Kubernetes & orchestration
secrets-store-csi-driver: Service account tokens written to driver logs
CVSS 6.5CVE-2023-2878Container, Kubernetes & orchestrationcurated
Impact
Service account tokens written to driver logs
Who can reach it
Anyone with log-pipeline read access
What to do
Upgrade the driver via DaemonSet rollout; rotate the exposed service-account tokens; scrub logs
References
Related entries
- KubeVirt: kubevirt-csi in OpenShift Virtualization HCP grants access to the root HCP worker node's volumeCVE-2024-1725 · KubeVirtMedium
- Argo CD: Repo-server DoS, halting all GitOps reconciliationCVE-2024-29893 · Argo CDMedium
- Docker / moby: NULL pointer dereference in image_history crashes the daemonCVE-2024-36620 · Docker / mobyMedium
- Docker / moby: Race in the buildkit snapshot adapterCVE-2024-36621 · Docker / mobyMedium
- azure-file-csi-driver: Service account tokens disclosed in driver logsCVE-2024-3744 · azure-file-csi-driverMedium
- Envoy: External clients manipulate Envoy internal headers, reaching unauthorized behaviourCVE-2024-45806 · EnvoyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.