PT-2023-16097 · Red Hat · Openshift
Sam Fowler
·
Published
2023-01-25
·
Updated
2023-02-16
·
CVE-2023-0229
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OpenShift versions 4.11 through 4.12
Description
A flaw was found in the apiserver-library-go package that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." The seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default" by default, which allows users to disable seccomp for pods they can create and modify.
Recommendations
For OpenShift versions 4.11 and 4.12, consider restricting the ability of low-privileged users to set the seccomp profile for pods they control to prevent potential exploitation. As a temporary workaround, consider disabling the use of the "unconfined" seccomp profile for pods until a patch is available. Restrict access to the restricted-v2 Security Context Constraint (SCC) to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift