Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5408

Опубликовано: 02 нояб. 2023
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.01112
Низкий

7.2 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.2
redhat
почти 3 года назад

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.

CVSS3: 7.2
msrc
почти 3 года назад

Openshift: modification of node role labels

CVSS3: 8.2
github
почти 3 года назад

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.

CVSS3: 8.2
fstec
почти 3 года назад

Уязвимость компонента Node Role Label Handler прикладного программного интерфейса корпоративной платформы Red Hat OpenShift Container Platform, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 63%
0.01112
Низкий

7.2 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo