CVE-2023-3955
HIGH8.8EPSS 0.76%Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils
發布日:2023/10/31修改日:2026/4/28
描述
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
受影響套件(4)
- Debian/kubernetesfrom 0, < 1.20.5+really1.20.2-1
- Go/k8s.io/kubernetes>= 1.28.0, < 1.28.1
- Go/k8s.io/kubernetesfrom 0, < 1.24.17, >= 1.25.0, < 1.25.13, >= 1.26.0, < 1.26.8, >= 1.27.0, < 1.27.5, >= 1.28.0, < 1.28.1
- Go/k8s.io/mount-utilsfrom 0, < 0.24.17, >= 0.25.0, < 0.25.13, >= 0.26.0, < 0.26.8, >= 0.27.0, < 0.27.5, >= 0.28.0, < 0.28.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
參考連結(18)
- ADVISORYhttps://github.com/advisories/GHSA-q78c-gwqw-jcmc
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-3955
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2023-3955
- PATCHhttps://github.com/kubernetes/kubernetes
- WEBhttps://github.com/kubernetes/kubernetes/commit/38c97fa67ed35f36e730856728c9e3807f63546a
- WEBhttps://github.com/kubernetes/kubernetes/commit/50334505cd27cbe7cf71865388f25a00e29b2596
- WEBhttps://github.com/kubernetes/kubernetes/commit/7da6d72c05dffb3b87e62e2bc8c3228ea12ba1b9
- WEBhttps://github.com/kubernetes/kubernetes/commit/b7547e28f898af37aa2f1107a49111f963250fe6
- WEBhttps://github.com/kubernetes/kubernetes/commit/c4e17abb04728e3a3f9bb26e727b0f978df20ec9
- WEBhttps://github.com/kubernetes/kubernetes/issues/119595
- WEBhttps://github.com/kubernetes/kubernetes/pull/120128
- WEBhttps://github.com/kubernetes/kubernetes/pull/120134
- WEBhttps://github.com/kubernetes/kubernetes/pull/120135
- WEBhttps://github.com/kubernetes/kubernetes/pull/120136
- WEBhttps://github.com/kubernetes/kubernetes/pull/120137
- WEBhttps://github.com/kubernetes/kubernetes/pull/120138
- WEBhttps://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E
- WEBhttps://security.netapp.com/advisory/ntap-20231221-0002