sigs.k8s.io/gcp-compute-persistent-disk-csi-driver is vulnerable to Authorization Bypass Through User-Controlled Key
91
Critical Risk
Affected versions of this package are vulnerable to authorization bypass through user-controlled keys due to insufficient validation in the emicklei/go-restful library before version 3.8.0. An attacker could exploit this weakness to gain unauthorized access to restricted resources.
You are affected if you are using a version that falls within the vulnerable range.
sigs.k8s.io/gcp-compute-persistent-disk-csi-driver is vulnerable to Authorization Bypass Through User-Controlled Key in versions 1.7.3 - 1.17.2.
Upgrade the sigs.k8s.io/gcp-compute-persistent-disk-csi-driver library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant