GO-2023-1763
Dashboard / Vulnerabilities / GO-2023-1763
GO-2023-1763
Summary: On a compromised node, the fluid-csi service account can be used to modify node specs in github.com/fluid-cloudnative/fluid
Details: On a compromised node, the fluid-csi service account can be used to modify node specs in github.com/fluid-cloudnative/fluid
References: https://github.com/fluid-cloudnative/fluid/security/advisories/GHSA-93xx-cvmc-9w3v, https://nvd.nist.gov/vuln/detail/CVE-2023-30840, https://github.com/fluid-cloudnative/fluid/commit/77c8110a3d1ec077ae2bce6bd88d296505db1550, https://github.com/fluid-cloudnative/fluid/commit/91c05c32db131997b5ca065e869c9918a125c149, https://github.com/fluid-cloudnative/fluid/releases/tag/v0.8.6
Affected packages
Package
Name: github.com/fluid-cloudnative/fluid
Purl: pkg:golang/github.com/fluid-cloudnative/fluid
Affected ranges
Type: SEMVER
Events:
