CVE-2023-1260
Summary
| CVE | CVE-2023-1260 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-24 01:15:00 UTC |
| Updated | 2023-12-15 18:19:00 UTC |
| Description | An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Kube-apiserver | - | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.11 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.12 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.13 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2023-1260 Kubernetes Vulnerability in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| Red Hat | MISC | access.redhat.com | |
| 2176267 – (CVE-2023-1260) CVE-2023-1260 kube-apiserver: PrivEsc | MISC | bugzilla.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| cve-details | MISC | access.redhat.com | |
| Red Hat | MISC | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 241784 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3976)
- 241856 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:4093)
- 241888 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2023:4312)
- 242359 Red Hat Update for red hat build of microshift 4.14.0 (RHSA-2023:5008)
- 770199 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3976)
- 770200 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:4093)
- 770201 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2023:4312)
- 995400 GO (Go) Security Update for github.com/openshift/apiserver-library-go (GHSA-92hx-3mh6-hc49)