PT-2023-3195 · Kops · Kops

James Cleverley-Prance

·

Publicado

2023-06-22

·

Atualizado

2024-08-21

·

CVE-2023-1943

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kOps (affected versions not specified)
Description The issue is related to errors in permission handling in the GCP Provider component of the kOps tool, which is used for automated management of Kubernetes virtual machine clusters. Exploitation of this issue can allow a remote attacker to escalate privileges by utilizing a container running in the cluster to access a Node service account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03305
CVE-2023-1943
GHSA-8GWJ-M6VH-2G6J
GO-2023-2125

Produtos afetados

Kops