CVE-2023-5528

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/11/2023
Last modified:
03/01/2025

Description

A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.8.0 (including) 1.25.16 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.26.0 (including) 1.26.11 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.27.0 (including) 1.27.8 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.28.0 (including) 1.28.4 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*