CVE-2023-3676

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
31/10/2023
Last modified:
13/02/2025

Description

A security issue was discovered in Kubernetes where a user<br /> that can create pods on Windows nodes may be able to escalate to admin <br /> privileges on those nodes. Kubernetes clusters are only affected if they<br /> include Windows nodes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.24.17 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.25.0 (including) 1.25.13 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.26.0 (including) 1.26.8 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.27.0 (including) 1.27.5 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.28.0 (including) 1.28.1 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*