Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc8m-28vv-4pjc

Опубликовано: 16 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.4

Описание

Kubelet vulnerable to bypass of seccomp profile enforcement

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.24.14

1.24.14

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.25.0, < 1.25.10

1.25.10

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.26.0, < 1.26.5

1.26.5

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.27.0, < 1.27.2

1.27.2

EPSS

Процентиль: 0%
0.00007
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-1287

Связанные уязвимости

CVSS3: 3.4
ubuntu
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
redhat
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
nvd
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
debian
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass ...

suse-cvrf
почти 2 года назад

Security update for kubernetes1.23

EPSS

Процентиль: 0%
0.00007
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-1287