SCA: security update for github.com/fluid-cloudnative/fluid (GHSA-93xx-cvmc-9w3v)

high Tenable Self-Hosted Container Security Plugin ID 413010

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-
intensive applications. Starting in version 0.7.0 and prior to version 0.8.6, if a malicious user gains
control of a Kubernetes node running fluid csi pod (controlled by the `csi-nodeplugin-fluid` node-
daemonset), they can leverage the fluid-csi service account to modify specs of all the nodes in the
cluster. However, since this service account lacks `list node` permissions, the attacker may need to use
other techniques to identify vulnerable nodes. Once the attacker identifies and modifies the node specs,
they can manipulate system-level-privileged components to access all secrets in the cluster or execute
pods on other nodes. This allows them to elevate privileges beyond the compromised node and potentially
gain full privileged access to the whole cluster. To exploit this vulnerability, the attacker can make all
other nodes unschedulable (for example, patch node with taints) and wait for system-critical components
with high privilege to appear on the compromised node. However, this attack requires two prerequisites: a
compromised node and identifying all vulnerable nodes through other means. Version 0.8.6 contains a patch
for this issue. As a workaround, delete the `csi-nodeplugin-fluid` daemonset in `fluid-system` namespace
and avoid using CSI mode to mount FUSE file systems. Alternatively, using sidecar mode to mount FUSE file
systems is recommended. (CVE-2023-30840)

See Also

https://github.com/advisories/GHSA-93xx-cvmc-9w3v

Plugin Details

Severity: High

ID: 413010

Version: Revision 1.11

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-30840

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/9/2023

Vulnerability Publication Date: 5/8/2023

Reference Information

CVE: CVE-2023-30840

cwe: CWE-863