VendorsLinux Foundationcubefsall versions
Vulnerabilities

Linux Foundation The Linux Foundation CubeFS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-46740
Insecure random string generator used for sensitive data
Published 2024-01-03 · Modified
9.8EPSS 0.004
CVE-2023-46741
CubeFS leaks magic secret key when starting Blobstore access service
Published 2024-01-03 · Modified
9.8EPSS 0.003
CVE-2023-46738
Authenticated users can crash the CubeFS servers with maliciously crafted requests
Published 2024-01-03 · Modified
6.5EPSS 0.006
CVE-2023-30512
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
Published 2023-04-12 · Modified
6.5EPSS 0.005
CVE-2023-46739
Timing attack can leak user passwords
Published 2024-01-03 · Modified
6.5EPSS 0.004
CVE-2023-46742
CubeFS leaks users key in logs
Published 2024-01-03 · Modified
6.5EPSS 0.003