CVE-2023-3893

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/11/2023
Last modified:
01/08/2025

Description

A security issue was discovered in Kubernetes where a user that can <br /> create pods on Windows nodes running kubernetes-csi-proxy may be able to<br /> escalate to admin privileges on those nodes. Kubernetes clusters are <br /> only affected if they include Windows nodes running <br /> kubernetes-csi-proxy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:csi_proxy:*:*:*:*:*:*:*:* 1.1.2 (including)
cpe:2.3:a:kubernetes:csi_proxy:2.0.0:alpha0:*:*:*:*:*:*