CVE-2023-3893

HIGH8.8EPSS 3.7%

Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation

發布日:2023/11/3修改日:2025/7/9
也稱為:GHSA-r6cc-7wj7-gfx2GO-2023-2176

描述

Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(9)