Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3893

Опубликовано: 23 авг. 2023
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

A vulnerability was found in Kubernetes. This flaw allows a user who can create pods on Windows nodes running kubernetes-csi-proxy to escalate to admin privileges on those nodes.

Отчет

Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy. Any Kubernetes environment with Windows nodes that are running kubernetes-csi-proxy is impacted. This is a common default configuration on Windows nodes. Run kubectl get nodes -l kubernetes.io/os=windows to see if any Windows nodes are in use.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4-wincw/windows-machine-config-rhel8-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2227129kubernetes: Insufficient input sanitization on kubernetes CSI proxy leads to privilege escalation

EPSS

Процентиль: 88%
0.03694
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

CVSS3: 8.8
nvd
больше 2 лет назад

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

CVSS3: 8.8
debian
больше 2 лет назад

A security issue was discovered in Kubernetes where a user that can c ...

CVSS3: 8.8
github
больше 2 лет назад

Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость компонента CSI Proxy программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 88%
0.03694
Низкий

8.8 High

CVSS3