Database/Container, Kubernetes & orchestration
secrets-store-csi-driver: Service account tokens written to driver logs
CVE-2023-2878Container, Kubernetes & orchestrationcurated
Impact
Service account tokens written to driver logs
Who can reach it
Anyone with log-pipeline read access
What to do
Upgrade the driver via DaemonSet rollout; rotate the exposed service-account tokens; scrub logs
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.