A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade sys-cluster/kubelet. | May 13, 2024 | Nov 14, 2023 |
| Kubernetes | — | Upgrade Kubernetes to version 1.26.11Upgrade Kubernetes to version 1.28.4Upgrade Kubernetes to version 1.25.16Upgrade Kubernetes to version 1.27.8 | Dec 4, 2023 | Nov 14, 2023 |
| Redhat Openshift | — | Upgrade windows-machine-config-rhel9-operatorUpgrade windows-machine-config-rhel8-operator | Dec 7, 2023 | Nov 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub