Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Kubernetes | — | Upgrade Kubernetes to version 1.9.0 | May 14, 2019 | May 18, 2018 |
| Redhat Openshift | — | Upgrade atomic-openshift-web-consoleUpgrade atomic-openshiftUpgrade cri-toolsUpgrade cri-oUpgrade openshift-ansibleUpgrade rubygem-fluent-plugin-elasticsearchUpgrade rubygem-fluent-plugin-kubernetes_metadata_filterUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-dockerregistry | Oct 8, 2019 | Apr 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub