A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-11-02T02:55:58.195Z
Updated: 2024-11-23T00:46:18.963Z
Reserved: 2023-10-04T17:58:23.775Z
Link: CVE-2023-5408
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-02T03:15:10.230
Modified: 2024-11-21T08:41:42.800
Link: CVE-2023-5408
Redhat