Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Kubernetes | — | Upgrade Kubernetes to version 1.9.0 | May 14, 2019 | May 18, 2018 |
| Redhat Openshift | — | Upgrade rubygem-fluent-plugin-elasticsearchUpgrade rubygem-fluent-plugin-kubernetes_metadata_filterUpgrade atomic-openshift-dockerregistryUpgrade golang-github-prometheus-node_exporterUpgrade cri-oUpgrade cri-toolsUpgrade atomic-openshift-web-consoleUpgrade atomic-openshiftUpgrade openshift-ansible | Oct 8, 2019 | Apr 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub