
SentinelOne Discovers Twin Path Traversal Vulnerabilities in Kubernetes CSI Drivers
SentinelOne researchers identified two path traversal vulnerabilities (CVE-2024-3177 and CVE-2024-3176) in Kubernetes Container Storage Interface (CSI) drivers, caused by a misconception in the filepath.Join function. These flaws allow attackers to perform cross-tenant file access by manipulating volume mount paths, potentially exposing sensitive data across Kubernetes clusters. The vulnerabilities affect CSI drivers that improperly sanitize user-supplied input when constructing file paths. No specific exploitation dates or affected vendor versions were disclosed, but the impact includes unauthorized read/write access to arbitrary files outside intended directories. The issues were disclosed to the Kubernetes Security Response Committee and relevant vendors for remediation.