{"api_version":"1","generated_at":"2026-04-23T02:36:32+00:00","cve":"CVE-2023-1260","urls":{"html":"https://cve.report/CVE-2023-1260","api":"https://cve.report/api/cve/CVE-2023-1260.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1260","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1260"},"summary":{"title":"CVE-2023-1260","description":"An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions \"update, patch\" the \"pods/ephemeralcontainers\" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2023-09-24 01:15:00","updated_at":"2023-12-15 18:19:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://security.netapp.com/advisory/ntap-20231020-0010/","name":"https://security.netapp.com/advisory/ntap-20231020-0010/","refsource":"MISC","tags":[],"title":"CVE-2023-1260 Kubernetes Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://access.redhat.com/errata/RHSA-2023:3976","name":"https://access.redhat.com/errata/RHSA-2023:3976","refsource":"MISC","tags":[],"title":"Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2176267","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2176267","refsource":"MISC","tags":[],"title":"2176267 – (CVE-2023-1260) CVE-2023-1260 kube-apiserver: PrivEsc","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2023:4312","name":"https://access.redhat.com/errata/RHSA-2023:4312","refsource":"MISC","tags":[],"title":"Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2023:4093","name":"https://access.redhat.com/errata/RHSA-2023:4093","refsource":"MISC","tags":[],"title":"Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2023-1260","name":"https://access.redhat.com/security/cve/CVE-2023-1260","refsource":"MISC","tags":[],"title":"cve-details","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2023:4898","name":"https://access.redhat.com/errata/RHSA-2023:4898","refsource":"MISC","tags":[],"title":"Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1260","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1260","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"1260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kubernetes","cpe5":"kube-apiserver","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"4.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"4.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"4.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"4.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-1260","qid":"241784","title":"Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3976)"},{"cve":"CVE-2023-1260","qid":"241856","title":"Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:4093)"},{"cve":"CVE-2023-1260","qid":"241888","title":"Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2023:4312)"},{"cve":"CVE-2023-1260","qid":"242359","title":"Red Hat Update for red hat build of microshift 4.14.0 (RHSA-2023:5008)"},{"cve":"CVE-2023-1260","qid":"770199","title":"Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3976)"},{"cve":"CVE-2023-1260","qid":"770200","title":"Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:4093)"},{"cve":"CVE-2023-1260","qid":"770201","title":"Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2023:4312)"},{"cve":"CVE-2023-1260","qid":"995400","title":"GO (Go) Security Update for github.com/openshift/apiserver-library-go (GHSA-92hx-3mh6-hc49)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-1260","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions \"update, patch\" the \"pods/ephemeralcontainers\" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Authentication Bypass Using an Alternate Path or Channel","cweId":"CWE-288"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"kubernetes","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"defaultStatus":"affected"}}]}}]}},{"vendor_name":"Red Hat","product":{"product_data":[{"product_name":"Red Hat OpenShift Container Platform 4.10","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"version":"0:4.10.0-202308291228.p0.g26fdcdf.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}],"defaultStatus":"affected"}}]}},{"product_name":"Red Hat OpenShift Container Platform 4.11","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"version":"0:4.11.0-202307200925.p0.ga9da4a8.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}],"defaultStatus":"affected"}}]}},{"product_name":"Red Hat OpenShift Container Platform 4.12","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"version":"0:4.12.0-202307040929.p0.g1485cc9.assembly.stream.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}],"defaultStatus":"affected"}}]}},{"product_name":"Red Hat OpenShift Container Platform 4.13","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"version":"0:4.13.0-202307132344.p0.gf245ced.assembly.stream.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}],"defaultStatus":"affected"}}]}},{"product_name":"Red Hat OpenShift Container Platform 4","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"defaultStatus":"affected"}},{"version_value":"not down converted","x_cve_json_5_version_data":{"defaultStatus":"unaffected"}},{"version_value":"not down converted","x_cve_json_5_version_data":{"defaultStatus":"unaffected"}},{"version_value":"not down converted","x_cve_json_5_version_data":{"defaultStatus":"unaffected"}}]}}]}}]}},"references":{"reference_data":[{"url":"https://access.redhat.com/errata/RHSA-2023:3976","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2023:3976"},{"url":"https://access.redhat.com/errata/RHSA-2023:4093","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2023:4093"},{"url":"https://access.redhat.com/errata/RHSA-2023:4312","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2023:4312"},{"url":"https://access.redhat.com/errata/RHSA-2023:4898","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2023:4898"},{"url":"https://access.redhat.com/security/cve/CVE-2023-1260","refsource":"MISC","name":"https://access.redhat.com/security/cve/CVE-2023-1260"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2176267","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2176267"},{"url":"https://security.netapp.com/advisory/ntap-20231020-0010/","refsource":"MISC","name":"https://security.netapp.com/advisory/ntap-20231020-0010/"}]},"work_around":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."}],"credits":[{"lang":"en","value":"This issue was discovered by Xingxing Xia (Red Hat)."}],"impact":{"cvss":[{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-09-24 01:15:00","lastModifiedDate":"2023-12-15 18:19:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH"},"exploitabilityScore":1.3,"impactScore":6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kubernetes:kube-apiserver:-:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}