CVE-2023-30617Medium· 6.5▾ SunlitKruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
Attacker that has gain root privilege of the node that kruise-daemon run , can leverage the kruise-daemon pod to list all secrets in the entire cluster. After that, attackers can leverage the "captured" secrets (e.g. the kruise-manager service account token) to gain extra privilege such as pod modification.
For users that do not require imagepulljob functions, they can modify kruise-daemon-role to drop the cluster level secret get/list privilege
For users who're using v0.8.x ~ v1.2.x, please update the v1.3.1 For users who're using v1.3, please update the v1.3.1 For users who're using v1.4, please update the v1.4.1 For users who're using v1.5, please update the v1.5.2
None
github.com/openkruise/kruise >= 0.8.0, < 1.3.1github.com/openkruise/kruise >= 1.4.0, < 1.4.1github.com/openkruise/kruise >= 1.5.0, < 1.5.2Upgrade to a patched release:
github.com/openkruise/kruise 1.3.1github.com/openkruise/kruise 1.4.1github.com/openkruise/kruise 1.5.2