VDB
Sign up
MEDIUM6.5

GHSA-qc2g-gmh6-95p4

kube-apiserver vulnerable to policy bypass

Quick fix

GHSA-qc2g-gmh6-95p4 — k8s.io/kubernetes: upgrade to the fixed version with the command below.

go get k8s.io/kubernetes@v1.27.3

Details

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/kubernetes
Introduced in: 1.27.0Fixed in: 1.27.3
Fixgo get k8s.io/kubernetes@v1.27.3
Go/k8s.io/kubernetes
Introduced in: 1.26.0Fixed in: 1.26.6
Fixgo get k8s.io/kubernetes@v1.26.6
Go/k8s.io/kubernetes
Introduced in: 1.25.0Fixed in: 1.25.11
Fixgo get k8s.io/kubernetes@v1.25.11
Go/k8s.io/kubernetes
Introduced in: 0Fixed in: 1.24.15
Fixgo get k8s.io/kubernetes@v1.24.15

References