Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-2728
HistoryJul 03, 2023 - 12:00 a.m.

CVE-2023-2728

2023-07-0300:00:00
ubuntu.com
ubuntu.com
13
cve-2023-2728
kubernetes
security policy
serviceaccount admission plugin
ephemeral containers

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

45.1%

Users may be able to launch containers that bypass the mountable secrets
policy enforced by the ServiceAccount admission plugin when using ephemeral
containers. The policy ensures pods running with a service account may only
reference secrets specified in the service accountโ€™s secrets field.
Kubernetes clusters are only affected if the ServiceAccount admission
plugin and the kubernetes.io/enforce-mountable-secrets annotation are
used together with ephemeral containers.

Notes

Author Note
leosilva kubernates is in fact a kubernetes installer that calls snap, not the package it self.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchkubernetes<ย anyUNKNOWN
ubuntu22.04noarchkubernetes<ย anyUNKNOWN
ubuntu24.04noarchkubernetes<ย anyUNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

45.1%