Record summary

CVE-2023-2727 has a selected CVSS score of 6.5 (medium).

Description

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 25, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE Listv1.24.14 to ≤ <=affected
v1.25.0 - v1.25.10affected
v1.26.0 - v1.26.5affected
v1.27.0 - v1.27.2affected
GitHub Advisory1.27.0 to < 1.27.3 · Fixed in 1.27.3affected
1.26.0 to < 1.26.6 · Fixed in 1.26.6affected
1.25.0 to < 1.25.11 · Fixed in 1.25.11affected
Before 1.24.15 · Fixed in 1.24.15affected

References

11