A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2793 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. |
Github GHSA |
GHSA-q78c-gwqw-jcmc | Kubernetes privilege escalation vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. |
Tue, 15 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubernetes kubelet
|
|
| CPEs | cpe:2.3:a:kubernetes:kubelet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kubernetes kubelet
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2025-02-13T17:03:13.470Z
Reserved: 2023-07-26T13:51:11.192Z
Link: CVE-2023-3955
Updated: 2024-08-02T07:08:50.695Z
Status : Modified
Published: 2023-10-31T21:15:08.613
Modified: 2025-02-13T17:17:00.000
Link: CVE-2023-3955
OpenCVE Enrichment
No data.
EUVD
Github GHSA