CVE-2023-30512: Linuxfoundation Cubefs

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.

Affected products

Published 2023-04-12. Last modified 2026-06-17.