Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0229

Опубликовано: 26 янв. 2023
Источник: nvd
CVSS3: 6.3
EPSS Низкий

Описание

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openshift:4.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift:4.12:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00086
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.3
redhat
около 3 лет назад

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.

CVSS3: 6.3
github
около 3 лет назад

github.com/openshift/apiserver-library-go Improper Input Validation vulnerability

EPSS

Процентиль: 25%
0.00086
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo