PT-2017-2596 · Kubernetes · Kubernetes

Liggitt

·

Published

2017-03-21

·

Updated

2025-08-08

·

CVE-2017-1000056

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kubernetes versions 1.5.0 through 1.5.4
Description The issue is related to a plugin for accessing PodSecurityPolicy, a software tool for managing clusters of virtual machines in Kubernetes, and is associated with insufficient access control. Exploitation of this issue may allow a remote attacker to escalate their privileges, granting them the ability to use any existing PodSecurityPolicy object.
Recommendations For Kubernetes versions 1.5.0 through 1.5.4, update to a version that includes a fix for the privilege escalation issue in the PodSecurityPolicy admission plugin. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2017-01812
CVE-2017-1000056
GHSA-2JX2-76RC-2V7V
GO-2023-1492
OPENSUSE-SU-2025:15424-1

Affected Products

Kubernetes