CVE-2023-2728
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers.
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- kubernetes/kubernetes
- Source
- jordan@liggitt.net
References
- http://www.openwall.com/lists/oss-security/2023/07/06/3Mailing List
- https://github.com/kubernetes/kubernetes/issues/118640Issue Tracking
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8Mailing List
- https://security.netapp.com/advisory/ntap-20230803-0004/
- http://www.openwall.com/lists/oss-security/2023/07/06/3Mailing List
- https://github.com/kubernetes/kubernetes/issues/118640Issue Tracking
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8Mailing List
- https://security.netapp.com/advisory/ntap-20230803-0004/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.