openwall.com
http://www.openwall.com/lists/oss-security/2023/07/06/2 CVE-2023-2727
MEDIUM
Bypassing policies imposed by the ImagePolicyWebhook admission plugin
Record summary
CVE-2023-2727 has a selected CVSS score of 6.5 (medium).
Description
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 25, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
KubernetesBrowse Kubernetes / KubernetesDefault status: unaffected | CVE List | v1.24.14 to ≤ <= | affected |
| v1.25.0 - v1.25.10 | affected | ||
| v1.26.0 - v1.26.5 | affected | ||
| v1.27.0 - v1.27.2 | affected | ||
k8s.io/kubernetesBrowse Go / k8s.io/kubernetes | GitHub Advisory | 1.27.0 to < 1.27.3 · Fixed in 1.27.3 | affected |
| 1.26.0 to < 1.26.6 · Fixed in 1.26.6 | affected | ||
| 1.25.0 to < 1.25.11 · Fixed in 1.25.11 | affected | ||
| Before 1.24.15 · Fixed in 1.24.15 | affected |
References
11github.com
https://github.com/kubernetes/kubernetes github.comissue tracking
https://github.com/kubernetes/kubernetes/issues/118640 github.com
https://github.com/kubernetes/kubernetes/pull/118356 github.com
https://github.com/kubernetes/kubernetes/pull/118471 github.com
https://github.com/kubernetes/kubernetes/pull/118473 github.com
https://github.com/kubernetes/kubernetes/pull/118474 github.com
https://github.com/kubernetes/kubernetes/pull/118512 groups.google.commailing list
https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2727 security.netapp.com
https://security.netapp.com/advisory/ntap-20230803-0004