CVE-2023-3893

HIGH8.8EPSS 3.7%

Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation

Published: 11/3/2023Modified: 7/9/2025
Also known as:GHSA-r6cc-7wj7-gfx2GO-2023-2176

Description

Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (9)