QID 377844
Date Published: 2023-01-04
QID 377844: Kubernetes Unauthorized Read of Custom Resources Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
Kubernetes kube-apiserver including and prior to v1.25.3
Kubernetes kube-apiserver including and prior to v1.24.7
Kubernetes kube-apiserver including and prior to v1.23.13
Kubernetes kube-apiserver including and prior to v1.22.15
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker to authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization.
Workaround:
This vulnerability can be mitigated by avoiding granting cluster-wide list and watch permissions.
CVEs related to QID 377844
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 113756 |
|