Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-2431

Опубликовано: 16 июн. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.4

Описание

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
jammy

not-affected

code not present
kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 1%
0.00009
Низкий

3.4 Low

CVSS3

Связанные уязвимости

CVSS3: 3.4
redhat
больше 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
nvd
больше 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVSS3: 3.4
debian
больше 2 лет назад

A security issue was discovered in Kubelet that allows pods to bypass ...

suse-cvrf
около 2 лет назад

Security update for kubernetes1.23

CVSS3: 4.4
github
больше 2 лет назад

Kubelet vulnerable to bypass of seccomp profile enforcement

EPSS

Процентиль: 1%
0.00009
Низкий

3.4 Low

CVSS3