CVE-2023-2728
Summary
| CVE | CVE-2023-2728 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-03 21:15:00 UTC |
| Updated | 2023-08-03 15:15:00 UTC |
| Description | Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Security Advisory] CVE-2023-2727: Bypassing policies imposed by the ImagePolicyWebhook admission plugin | MISC | groups.google.com | |
| CVE-2023-2727, CVE-2023-2728: Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin · Issue #118640 · kubernetes/kubernetes · GitHub | MISC | github.com | |
| oss-security - [kubernetes] CVE-2023-2728: Bypassing enforce mountable secrets policy imposed by the ServiceAccount admission plugin Rita Zhang <[email protected]> | MISC | www.openwall.com | |
| July 2023 Kubernetes Vulnerabilities in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160760 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12562)
- 160761 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12563)
- 160762 Oracle Enterprise Linux Security Update for olcne (ELSA-2023-25546)
- 160763 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12564)
- 160764 Oracle Enterprise Linux Security Update for olcne (ELSA-2023-25545)
- 160765 Oracle Enterprise Linux Security Update for kubernetes (ELSA-2023-12561)
- 183923 Debian Security Update for kubernetes (CVE-2023-2728)
- 242359 Red Hat Update for red hat build of microshift 4.14.0 (RHSA-2023:5008)
- 503195 Alpine Linux Security Update for k3s
- 506103 Alpine Linux Security Update for k3s
- 754112 SUSE Enterprise Linux Security Update for kubernetes1.23 (SUSE-SU-2023:2542-1)
- 754113 SUSE Enterprise Linux Security Update for kubernetes1.18 (SUSE-SU-2023:2541-1)