VDB
Sign up
HIGH8.0

GHSA-92hx-3mh6-hc49

kube-apiserver authentication bypass vulnerability

Quick fix

GHSA-92hx-3mh6-hc49 — github.com/openshift/apiserver-library-go: upgrade to the fixed version with the command below.

go get github.com/openshift/apiserver-library-go@v0.0.0-20230621

Details

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/openshift/apiserver-library-go
Introduced in: 0Fixed in: 0.0.0-20230621
Fixgo get github.com/openshift/apiserver-library-go@v0.0.0-20230621

References