Описание
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
A flaw was found in Kubernetes. This vulnerability allows a user with create pod permissions to exploit gitRepo volumes to access local git repositories belonging to other pods on the same node.
Отчет
This vulnerability is rated as moderate severity because it affects Kubernetes clusters using the deprecated in-tree gitRepo volume feature, which allows cloning git repositories from other pods within the same node. Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-280: Improper Handling of Insufficient Permissions or Privileges vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Access enforcement and least privilege controls ensure that only authorized users and processes can access sensitive services, reducing the risk of unauthorized privilege use. Role-based access control (RBAC) and defined security boundaries at the platform level prevent privilege escalation by isolating workloads and enforcing permission policies. Process isolation further contains unauthorized actions within individual containers. Configuration management ensures consistent application of access policies across updates and deployments. Additionally, runtime monitoring, audit logging, and malicious code protection detect and respond to unauthorized access attempts, minimizing the likelihood and impact of insufficient privilege enforcement.
Меры по смягчению последствий
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-supported-rhel9 | Fix deferred | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/platform-resource-runner-rhel8 | Fix deferred | ||
Red Hat Ansible Automation Platform 2 | automation-controller | Fix deferred | ||
Red Hat Discovery 1 | discovery-server-container | Fix deferred | ||
Red Hat Enterprise Linux 10 | fence-agents | Fix deferred | ||
Red Hat Enterprise Linux 9 | fence-agents | Fix deferred | ||
Red Hat OpenShift AI (RHOAI) | rhoai/odh-kf-notebook-controller-rhel8 | Fix deferred | ||
Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-api-server-v2-rhel8 | Fix deferred | ||
Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-driver-rhel8 | Fix deferred | ||
Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-launcher-rhel8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
This CVE only affects Kubernetes clusters that utilize the in-tree git ...
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Уязвимость функции gitRepo программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации
EPSS
6.5 Medium
CVSS3