kube-apiserver authentication bypass vulnerability
High severity
GitHub Reviewed
Published
Sep 24, 2023
to the GitHub Advisory Database
•
Updated May 3, 2024
Package
Affected versions
< 0.0.0-20230621
Patched versions
0.0.0-20230621
Description
Published by the National Vulnerability Database
Sep 24, 2023
Published to the GitHub Advisory Database
Sep 24, 2023
Reviewed
Sep 25, 2023
Last updated
May 3, 2024
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.
References