PT-2023-16844 · Kubernetes · Kube-Apiserver

Nick Tait

+1

·

Published

2023-09-24

·

Updated

2024-05-03

·

CVE-2023-1260

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kube-apiserver (affected versions not specified)
Description An authentication bypass issue was discovered in kube-apiserver, allowing a remote, authenticated attacker with update, patch permissions on the pods/ephemeralcontainers subresource to potentially evade SCC admission restrictions. This could enable them to gain control of a privileged pod by creating a new pod or patching an existing one they have access to.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2023-1260
GHSA-92HX-3MH6-HC49
RHSA-2023:3976
RHSA-2023:4093
RHSA-2023:4312
RHSA-2023:4898
RHSA-2023:5008

Affected Products

Kube-Apiserver