CVE-2023-3955
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-3955
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1.20.5+really1.20.2-1 |
| debian | bullseye | fixed | 1.20.5+really1.20.2-1 |
| debian | forky | fixed | 1.20.5+really1.20.2-1 |
| debian | sid | fixed | 1.20.5+really1.20.2-1 |
| debian | trixie | fixed | 1.20.5+really1.20.2-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | >=1.28.0,<1.28.1 | 1.28.1 |
| Go | k8s.io/kubernetes | >=1.27.0,<1.27.5 | 1.27.5 |
| Go | k8s.io/kubernetes | >=1.26.0,<1.26.8 | 1.26.8 |
| Go | k8s.io/kubernetes | >=1.25.0,<1.25.13 | 1.25.13 |
| Go | k8s.io/kubernetes | <1.24.17 | 1.24.17 |
| Go | k8s.io/mount-utils | >=0.28.0,<0.28.1 | 0.24.17 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-3955
- https://github.com/kubernetes/kubernetes/issues/119595
- https://github.com/kubernetes/kubernetes/pull/120128
- https://github.com/kubernetes/kubernetes/pull/120134
- https://github.com/kubernetes/kubernetes/pull/120135
- https://github.com/kubernetes/kubernetes/pull/120136
- https://github.com/kubernetes/kubernetes/pull/120137
- https://github.com/kubernetes/kubernetes/pull/120138
- https://github.com/kubernetes/kubernetes/commit/38c97fa67ed35f36e730856728c9e3807f63546a
- https://github.com/kubernetes/kubernetes/commit/50334505cd27cbe7cf71865388f25a00e29b2596
- https://github.com/kubernetes/kubernetes/commit/7da6d72c05dffb3b87e62e2bc8c3228ea12ba1b9
- https://github.com/kubernetes/kubernetes/commit/b7547e28f898af37aa2f1107a49111f963250fe6
- https://github.com/kubernetes/kubernetes/commit/c4e17abb04728e3a3f9bb26e727b0f978df20ec9
- https://github.com/kubernetes/kubernetes
- https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E
- https://security.netapp.com/advisory/ntap-20231221-0002
- https://github.com/advisories/GHSA-q78c-gwqw-jcmc
- https://security-tracker.debian.org/tracker/CVE-2023-3955
Verify integrity in audit chain (admin only). AS-IS.