CVE-2023-30617 Information

Description

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1 1.4.1 and 1.5.2 an attacker who has gained root privilege of the node that kruise-daemon run can leverage the kruise-daemon pod to list all secrets in the entire cluster. After that the attacker can leverage the ## Reference https://github.com/openkruise/kruise/security/advisories/GHSA-437m-7hj5-9mpw

Share on: