CVE-2023-2878
MediumAdvisory
Published 26 May 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.004
- 31st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4
- of 17,781 indexed, latest versions
- Container images
- 4
- deployed by those charts
- Fix available
- 1 of 1
- affected package
secrets-store-csi-driver discloses service account tokens in logs
Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 4 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| sigs.k8s.io/ | v0.0.0-20260226185025-7ba4394578c8, v0.0.19, v0.0.22, v1.2.3 | 1.3.3 | 4 |
- OSV records
- GHSA-g82w-58jf-gcxx
- Also known as
- GO-2023-1793
Charts affected
4 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher | 1.8.2 | 1 of 5See more | 2,235 |
| secrets-store-csi-driver-provider-awsportefaix-hub | 0.4.0 | 1 of 1See more | 2,206 |
| secrets-store-csi-driver-provider-awscustom | 0.2.0 | 1 of 1See more | 1,232 |
| aws-secretssecretsprovider | 0.1.0 | 1 of 1See more | 2,213 |
Container images carrying it
4 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| mcr.microsoft.com/ | 5f91243cfd60 | sigs.k8s.io/ | 1.3.3 | 1 |
| public.ecr.aws/ | 02aed3370fce | sigs.k8s.io/ | 1.3.3 | 1 |
| public.ecr.aws/ | 363bd65cd707 | sigs.k8s.io/ | 1.3.3 | 1 |
| public.ecr.aws/ | b32c99e7bc45 | sigs.k8s.io/ | 1.3.3 | 1 |