Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2025-4563

около 1 года назад

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

CVSS3: 2.7
EPSS: Низкий
redhat логотип

CVE-2025-4563

около 1 года назад

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2025-4563

около 1 года назад

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

CVSS3: 2.7
EPSS: Низкий
msrc логотип

CVE-2025-4563

12 месяцев назад

Nodes can bypass dynamic resource allocation authorization checks

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2025-4563

около 1 года назад

A vulnerability exists in the NodeRestriction admission controller whe ...

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-hj2p-8wj8-pfq4

около 1 года назад

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-4563

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

CVSS3: 2.7
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-4563

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

CVSS3: 2.7
1%
Низкий
около 1 года назад
nvd логотип
CVE-2025-4563

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

CVSS3: 2.7
1%
Низкий
около 1 года назад
msrc логотип
CVE-2025-4563

Nodes can bypass dynamic resource allocation authorization checks

CVSS3: 2.7
1%
Низкий
12 месяцев назад
debian логотип
CVE-2025-4563

A vulnerability exists in the NodeRestriction admission controller whe ...

CVSS3: 2.7
1%
Низкий
около 1 года назад
github логотип
GHSA-hj2p-8wj8-pfq4

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

CVSS3: 2.7
1%
Низкий
около 1 года назад

Уязвимостей на страницу