CVE-2023-2728
03.07.2023, 21:15
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service accounts secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.Enginsight
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | 𝑥 ≤ 1.24.14 |
kubernetes | kubernetes | 1.25.0 ≤ 𝑥 ≤ 1.25.10 |
kubernetes | kubernetes | 1.26.0 ≤ 𝑥 ≤ 1.26.5 |
kubernetes | kubernetes | 1.27.0 ≤ 𝑥 ≤ 1.27.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References