Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43813
HistoryOct 13, 2023 - 9:10 a.m.

Privilege Escalation

2023-10-1309:10:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
kops
privilege escalation
gcp provider
gossip mode
node service account
container
sensitive information
state storage bucket
cluster-admin permissions

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

21.5%

kOps is vulnerable to Privilege Escalation. The vulnerability is caused when running kOps with the GCP Provider in Gossip Mode, where Node service account credentials could be used by a container running in the cluster to retrieve sensitive information from the state storage bucket and escalate to cluster-admin permissions.

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

21.5%