CVE-2025-62878
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
10.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Description
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-23
Source
GitHub
Vendor
go
Product
github.com/rancher/local-path-provisioner
Discussion (0)
Add Comment
No comments yet. Be the first!