Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1260

Опубликовано: 04 апр. 2023
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-openshift-apiserver-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-podNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-testsNot affected
Red Hat OpenShift Container Platform 4.10openshiftFixedRHSA-2023:489806.09.2023
Red Hat OpenShift Container Platform 4.11openshiftFixedRHSA-2023:431202.08.2023
Red Hat OpenShift Container Platform 4.12openshiftFixedRHSA-2023:397612.07.2023
Red Hat OpenShift Container Platform 4.13openshiftFixedRHSA-2023:409320.07.2023
Red Hat OpenShift Container Platform 4.14microshiftFixedRHSA-2023:500831.10.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-288

EPSS

Процентиль: 18%
0.00058
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
больше 2 лет назад

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.

CVSS3: 8
github
больше 2 лет назад

kube-apiserver authentication bypass vulnerability

EPSS

Процентиль: 18%
0.00058
Низкий

8 High

CVSS3