CVE-2023-2431
LOWKubernetes < 1.24.14 - Seccomp Profile Enforcement Bypass via Empty Profile Field
Title source: llmDescription
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.
References (4)
Core 4
Core References
Issue Tracking
https://github.com/kubernetes/kubernetes/issues/118690
Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/XBX4RL4UOC7JHWWYB2AJCKSUM7EG5Y5G/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/43HDSKBKPSW53OW647B5ETHRWFFNHSRQ/
Scores
CVSS v3
3.4
EPSS
0.0024
EPSS Percentile
15.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1287
Status
published
Products (3)
fedoraproject/fedora
38
k8s.io/kubernetes
0 - 1.24.14Go
kubernetes/kubernetes
< 1.24.14
Published
Jun 16, 2023
Tracked Since
Feb 18, 2026