Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46594
HistoryApr 23, 2024 - 6:57 p.m.

Improper Input Validation

2024-04-2318:57:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
kubernetes
vulnerability
input validation
containers
secrets
service account
admission plugin

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.4

Confidence

High

EPSS

0

Percentile

9.6%

Kubernetes is vulnerable to Improper Input Validation. The vulnerability is due to containers, init containers, and ephemeral containers with the envFrom field populated bypassing the mountable secrets policy, which ensures that pods running with a service account may only reference secrets specified in the service accountโ€™s secrets field. Kubernetes clusters are affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with the mentioned containers.

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.4

Confidence

High

EPSS

0

Percentile

9.6%