MEDIUM6.5
GHSA-cgcv-5272-97pr
Kubernetes mountable secrets policy bypass
Quick fix
GHSA-cgcv-5272-97pr — k8s.io/kubernetes: upgrade to the fixed version with the command below.
go get k8s.io/kubernetes@v1.27.3Details
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-2728[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/118640[WEB]
- https://github.com/kubernetes/kubernetes/pull/118356[WEB]
- https://github.com/kubernetes/kubernetes/pull/118471[WEB]
- https://github.com/kubernetes/kubernetes/pull/118473[WEB]
- https://github.com/kubernetes/kubernetes/pull/118474[WEB]
- https://github.com/kubernetes/kubernetes/pull/118512[WEB]
- https://github.com/kubernetes/kubernetes[PACKAGE]
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8[WEB]
- https://security.netapp.com/advisory/ntap-20230803-0004[WEB]
- http://www.openwall.com/lists/oss-security/2023/07/06/3[WEB]