CVE-2023-1260

Aliases:GHSA-92hx-3mh6-hc49
Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 24 Sept 2023, 00:07
Last modified:02 Aug 2024, 05:40

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
8 HIGH
v3.1 (cve.org)
EPSS Score
0.06% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Sept 2023, 00:07
Published
Vulnerability first disclosed
02 Aug 2024, 05:40
Last Modified
Vulnerability information updated

Description

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.

CVSS Metrics

  • v3.1HIGHScore: 8CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.06% Percentile: 20%

Techniques & Countermeasures

  • CWE-288Authentication Bypass Using an Alternate Path or Channel

    The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Systems

  • github.com/openshiftapiserver-library-go

    < 0.0.0-20230621

  • kuberneteskube-apiserver

    na

  • redhatopenshift_container_platform

    4.10 | 4.11 | 4.12 | 4.13

References (13)