VulnerabilityModified
CVE-2023-2727
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers.
MEDIUM 6.5EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- kubernetes/kubernetes
- Source
- jordan@liggitt.net
References
- http://www.openwall.com/lists/oss-security/2023/07/06/2Mailing List, Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/118640Issue Tracking
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8Mailing List
- https://security.netapp.com/advisory/ntap-20230803-0004/
- http://www.openwall.com/lists/oss-security/2023/07/06/2Mailing List, Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/118640Issue Tracking
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8Mailing List
- https://security.netapp.com/advisory/ntap-20230803-0004/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.