Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x4m-3c2p-qppc

Опубликовано: 27 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.7

Описание

Kubernetes Nodes can delete themselves by adding an OwnerReference

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.31.12

1.31.12

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.32.0-alpha.0, < 1.32.7

1.32.8

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.33.0-alpha.0, < 1.33.4

1.33.4

EPSS

Процентиль: 4%
0.00021
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.7
ubuntu
2 месяца назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
redhat
3 месяца назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
nvd
2 месяца назад

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

CVSS3: 6.7
debian
2 месяца назад

A vulnerability exists in the NodeRestriction admission controller in ...

CVSS3: 6.7
fstec
3 месяца назад

Уязвимость плагина NodeRestriction сервера kube-apiserver программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 4%
0.00021
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-863