Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-3177
HistoryApr 22, 2024 - 12:00 a.m.

CVE-2024-3177

2024-04-2200:00:00
ubuntu.com
ubuntu.com
8
kubernetes
secrets policy
serviceaccount admission plugin
envfrom field
ephemeral containers.

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.8

Confidence

High

EPSS

0

Percentile

9.6%

A security issue was discovered in Kubernetes where users may be able to
launch containers that bypass the mountable secrets policy enforced by the
ServiceAccount admission plugin when using containers, init containers, and
ephemeral containers with the envFrom field populated. The policy ensures
pods running with a service account may only reference secrets specified in
the service accountโ€™s secrets field. Kubernetes clusters are only affected
if the ServiceAccount admission plugin and the
kubernetes.io/enforce-mountable-secrets annotation are used together with
containers, init containers, and ephemeral containers with the envFrom
field populated.

Notes

Author Note
leosilva kubernates is in fact a kubernetes installer that calls snap, not the package it self.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchkubernetes<ย anyUNKNOWN
ubuntu22.04noarchkubernetes<ย anyUNKNOWN
ubuntu24.04noarchkubernetes<ย anyUNKNOWN

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.8

Confidence

High

EPSS

0

Percentile

9.6%