CVE-2023-2727
Summary
| CVE | CVE-2023-2727 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-03 21:15:00 UTC |
| Updated | 2023-08-03 15:15:00 UTC |
| Description | Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - [kubernetes] CVE-2023-2727: Bypassing policies imposed by the ImagePolicyWebhook admission plugin | MISC | www.openwall.com | |
| [Security Advisory] CVE-2023-2727: Bypassing policies imposed by the ImagePolicyWebhook admission plugin | MISC | groups.google.com | |
| CVE-2023-2727, CVE-2023-2728: Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin · Issue #118640 · kubernetes/kubernetes · GitHub | MISC | github.com | |
| July 2023 Kubernetes Vulnerabilities in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160760 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12562)
- 160761 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12563)
- 160762 Oracle Enterprise Linux Security Update for olcne (ELSA-2023-25546)
- 160763 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12564)
- 160764 Oracle Enterprise Linux Security Update for olcne (ELSA-2023-25545)
- 160765 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12561)
- 181950 Debian Security Update for kubernetes (CVE-2023-2727)
- 242359 Red Hat Update for red hat build of microshift 4.14.0 (RHSA-2023:5008)
- 754112 SUSE Enterprise Linux Security Update for kubernetes1.23 (SUSE-SU-2023:2542-1)
- 754113 SUSE Enterprise Linux Security Update for kubernetes1.18 (SUSE-SU-2023:2541-1)