CVE-2023-30840 is a high-severity vulnerability affecting Fluid, an open-source Kubernetes-native distributed dataset orchestrator, in versions 0.7.0 through 0.8.5. A malicious user with control of a Kubernetes node running the fluid csi pod can leverage its service account to modify node specifications, potentially leading to privilege escalation and full cluster compromise. While requiring a compromised node and external methods to identify vulnerable nodes, successful exploitation could allow attackers to access all secrets or execute pods on other nodes. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.7.0, < 0.8.6CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:fluid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.