A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade kubernetes | Jul 30, 2024 | Oct 31, 2023 |
| Kubernetes | — | Upgrade Kubernetes to version 1.26.8Upgrade Kubernetes to version 1.27.5Upgrade Kubernetes to version 1.25.13Upgrade Kubernetes to version 1.24.17Upgrade Kubernetes to version 1.28.1 | Nov 13, 2023 | Oct 31, 2023 |
| Redhat Openshift | — | Upgrade windows-machine-config-rhel9-operatorUpgrade windows-machine-config-rhel8-operator | Aug 29, 2023 | Aug 23, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub