CVE-2023-30512

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/04/2023
Last modified:
07/02/2025

Description

CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:cubefs:*:*:*:*:*:*:*:* 3.2.1 (including)