PT-2023-3195 · Kops · Kops

James Cleverley-Prance

·

Published

2023-06-22

·

Updated

2024-08-21

·

CVE-2023-1943

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kOps (affected versions not specified)
Description The issue is related to errors in permission handling in the GCP Provider component of the kOps tool, which is used for automated management of Kubernetes virtual machine clusters. Exploitation of this issue can allow a remote attacker to escalate privileges by utilizing a container running in the cluster to access a Node service account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2023-03305
CVE-2023-1943
GHSA-8GWJ-M6VH-2G6J
GO-2023-2125

Affected Products

Kops