Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-2431
HistoryJun 16, 2023 - 12:00 a.m.

CVE-2023-2431

2023-06-1600:00:00
ubuntu.com
ubuntu.com
25
kubelet bypass seccomp
pods unconfined mode
security issue
localhost type
empty profile field

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

15.7%

A security issue was discovered in Kubelet that allows pods to bypass the
seccomp profile enforcement. Pods that use localhost type for seccomp
profile but specify an empty profile field, are affected by this issue. In
this scenario, this vulnerability allows the pod to run in unconfined
(seccomp disabled) mode. This bug affects Kubelet.

Notes

Author Note
leosilva kubernates is in fact a kubernetes installer that calls snap, not the package it self.

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

15.7%