CVE-2023-5528
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-5528
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 0 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 0 |
| debian | sid | fixed | 0 |
| debian | trixie | fixed | 0 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | >=1.28.0,<1.28.4 | 1.28.4 |
| Go | k8s.io/kubernetes | >=1.27.0,<1.27.8 | 1.27.8 |
| Go | k8s.io/kubernetes | >=1.26.0,<1.26.11 | 1.26.11 |
| Go | k8s.io/kubernetes | <1.25.16 | 1.25.16 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-5528
- https://github.com/kubernetes/kubernetes/issues/121879
- https://github.com/kubernetes/kubernetes/pull/121881
- https://github.com/kubernetes/kubernetes/pull/121882
- https://github.com/kubernetes/kubernetes/pull/121883
- https://github.com/kubernetes/kubernetes/pull/121884
- https://github.com/kubernetes/kubernetes/pull/121885
- https://github.com/kubernetes/kubernetes
- https://groups.google.com/g/kubernetes-security-announce/c/SL_d4NR8pzA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JH444PWZBINXLLFV7XLIJIZJHSK6UEZ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4XZIX727JIKF5RQW7RVVBLWXBCDIBJA7
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MPGMITSZXUCAVO7Q75675SOLXC2XXU4
- https://security.netapp.com/advisory/ntap-20240119-0009
- https://github.com/advisories/GHSA-hq6q-c2x6-hmch
- https://security-tracker.debian.org/tracker/CVE-2023-5528
Verify integrity in audit chain (admin only). AS-IS.