Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-46167

Опубликовано: 02 дек. 2022
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with PATCH capabilities on its own Namespace, is able to edit it and remove the Owner Reference, breaking the reconciliation of the Capsule Operator and removing all the enforcement like Pod Security annotations, Network Policies, Limit Range and Resource Quota items. An attacker could detach the Namespace from a Tenant that is forbidding starting privileged Pods using the Pod Security labels by removing the OwnerReference, removing the enforcement labels, and being able to start privileged containers that would be able to start a generic Kubernetes privilege escalation. Patches have been released for version 0.1.3. No known workarounds are available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:clastix:capsule:*:*:*:*:*:*:*:*
Версия до 0.1.3 (исключая)

EPSS

Процентиль: 61%
0.00413
Низкий

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
github
около 3 лет назад

Capsule vulnerable to privilege escalation by ServiceAccount deployed in a Tenant Namespace

EPSS

Процентиль: 61%
0.00413
Низкий

8.8 High

CVSS3

Дефекты

CWE-863