Lucene search

K
redhatcveRedhat.comRH:CVE-2023-1943
HistoryJun 22, 2023 - 10:22 a.m.

CVE-2023-1943

2023-06-2210:22:53
redhat.com
access.redhat.com
13
kubernetes
kops
remote attacker
elevated privileges
gce
gcp
gossip mode
authenticated
vulnerability
cluster-admin permissions

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

21.5%

A flaw was found in the Kubernetes kOps. Affected versions of Kubernetes kOps could allow a remote authenticated attacker to gain elevated privileges on the system caused by a vulnerability when using the GCE/GCP Provider in Gossip Mode. By sending a specially-crafted request, an authenticated attacker can gain elevated privileges to cluster-admin permissions.

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

21.5%