Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41133
HistoryJul 06, 2023 - 10:13 a.m.

Policy Bypass

2023-07-0610:13:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
kubernetes
policy bypass
vulnerability
ephemeral containers
serviceaccount admission plugin
restricted images
cluster impact
enforce-mountable-secrets annotation

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

45.1%

github.com/kubernetes/kubernetes is vulnerable to Policy Bypass. The vulnerability exists in serviceaccount/admission.go, when ephemeral containers are used, which allows malicious users to start containers using restricted images, impacting the cluster if the ServiceAccount admission plugin is utilized as well as the kubernetes.io/enforce-mountable-secrets annotation.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

45.1%