Lucene search

K
redhatRedHatRHSA-2023:1893
HistoryApr 20, 2023 - 1:44 a.m.

(RHSA-2023:1893) Critical: Multicluster Engine for Kubernetes 2.0 hotfix security update for console

2023-04-2001:44:20
access.redhat.com
35
multicluster engine
kubernetes 2.0
security update
sandbox escape
cve-2023-29017
cve-2023-29199
cve-2023-30547
exception sanitization
unix

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

0.017 Low

EPSS

Percentile

87.9%

Security Fix(es)

  • CVE-2023-29017 vm2: Sandbox Escape
  • CVE-2023-29199 vm2: Sandbox Escape
  • CVE-2023-30547 vm2: Sandbox Escape when exception sanitization

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

0.017 Low

EPSS

Percentile

87.9%