CVE-2023-2727
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-2727
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-2727.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 1.20.5+really1.20.2-1 |
| debian | bullseye | fixed | 1.20.5+really1.20.2-1 |
| debian | forky | fixed | 1.20.5+really1.20.2-1 |
| debian | sid | fixed | 1.20.5+really1.20.2-1 |
| debian | trixie | fixed | 1.20.5+really1.20.2-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | >=1.27.0,<1.27.3 | 1.27.3 |
| Go | k8s.io/kubernetes | >=1.26.0,<1.26.6 | 1.26.6 |
| Go | k8s.io/kubernetes | >=1.25.0,<1.25.11 | 1.25.11 |
| Go | k8s.io/kubernetes | <1.24.15 | 1.24.15 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-2727
- https://github.com/kubernetes/kubernetes/issues/118640
- https://github.com/kubernetes/kubernetes/pull/118356
- https://github.com/kubernetes/kubernetes/pull/118471
- https://github.com/kubernetes/kubernetes/pull/118473
- https://github.com/kubernetes/kubernetes/pull/118474
- https://github.com/kubernetes/kubernetes/pull/118512
- https://github.com/kubernetes/kubernetes
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8
- https://security.netapp.com/advisory/ntap-20230803-0004
- http://www.openwall.com/lists/oss-security/2023/07/06/2
- https://github.com/advisories/GHSA-qc2g-gmh6-95p4
- https://www.suse.com/security/cve/CVE-2023-2727.html
- https://security-tracker.debian.org/tracker/CVE-2023-2727
Verify integrity in audit chain (admin only). AS-IS.