« Volver al listado

CVE-2025-58061

Estado: AplazadaMedia (5.5)—

OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world readable and that would allow non-privileged users to access sensitive data such as databases of k8s workload. The rawfile-localpv storage class creates persistent volume data under /var/csi/rawfile/ on Kubernetes hosts by default. However, the directory and data in it are world-readable. It allows non-privileged users to access the whole persistent volume data, and those can include sensitive information such as a whole database if the Kubernetes tenants are running MySQL or PostgreSQL in a container so it could lead to a database breach. This issue has been patched in version 0.10.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-58061",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-58061",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-29T13:23:46.128507Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "openebs",
          "product": "rawfile-localpv",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.10.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-08-28T22:15:32.773",
  "references": [
    {
      "url": "https://github.com/openebs/rawfile-localpv/security/advisories/GHSA-wh95-vw4r-xwx4",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world readable and that would allow non-privileged users to access sensitive data such as databases of k8s workload. The rawfile-localpv storage class creates persistent volume data under /var/csi/rawfile/ on Kubernetes hosts by default. However, the directory and data in it are world-readable. It allows non-privileged users to access the whole persistent volume data, and those can include sensitive information such as a whole database if the Kubernetes tenants are running MySQL or PostgreSQL in a container so it could lead to a database breach. This issue has been patched in version 0.10.0."
    },
    {
      "lang": "es",
      "value": "OpenEBS Local PV RawFile permite la implementación dinámica de volúmenes y sistemas de archivos persistentes con estado, locales al nodo, para Kubernetes. Antes de la versión 0.10.0, los datos del volumen persistente son legibles por cualquier usuario y eso permitiría a usuarios no privilegiados acceder a datos sensibles como las bases de datos de la carga de trabajo de k8s. La clase de almacenamiento rawfile-localpv crea datos de volumen persistente bajo /var/csi/rawfile/ en los hosts de Kubernetes por defecto. Sin embargo, el directorio y los datos que contiene son legibles por cualquier usuario. Permite a usuarios no privilegiados acceder a todos los datos del volumen persistente, y estos pueden incluir información sensible como una base de datos completa si los inquilinos de Kubernetes están ejecutando MySQL o PostgreSQL en un contenedor, lo que podría llevar a una violación de la base de datos. Este problema ha sido parcheado en la versión 0.10.0."
    }
  ],
  "lastModified": "2026-06-17T09:43:51.483",
  "sourceIdentifier": "security-advisories@github.com"
}