QID 996548
QID 996548: GO (Go) Security Update for github.com/openkruise/kruise (GHSA-437m-7hj5-9mpw)
Attacker that has gain root privilege of the node that kruise-daemon run , can leverage the kruise-daemon pod to list all secrets in the entire cluster. After that, attackers can leverage the "captured" secrets (e.g. the kruise-manager service account token) to gain extra privilege such as pod modification.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-437m-7hj5-9mpw for updates and patch information.
Vendor References
- GHSA-437m-7hj5-9mpw -
github.com/advisories/GHSA-437m-7hj5-9mpw
CVEs related to QID 996548
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-437m-7hj5-9mpw | github.com/openkruise/kruise |
|