Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2431

Опубликовано: 16 июн. 2023
Источник: nvd
CVSS3: 3.4
CVSS3: 5.5
EPSS Низкий

Описание

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия до 1.24.14 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.25.0 (включая) до 1.25.10 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.26.0 (включая) до 1.26.5 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.27.0 (включая) до 1.27.2 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

EPSS

Процентиль: 0%
0.00007
Низкий

3.4 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-1287
NVD-CWE-Other

Связанные уязвимости

CVSS3: 3.4
ubuntu
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
redhat
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
debian
около 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass ...

suse-cvrf
почти 2 года назад

Security update for kubernetes1.23

CVSS3: 4.4
github
около 2 лет назад

Kubelet vulnerable to bypass of seccomp profile enforcement

EPSS

Процентиль: 0%
0.00007
Низкий

3.4 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-1287
NVD-CWE-Other