CVE-2023-32191
EUVD-2024-195016.10.2024, 13:15
When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| suse | rke | 1.4.18 ≤ 𝑥 < 1.4.19 | ADP |
| suse | rke | 1.5.9 ≤ 𝑥 < 1.5.10 | ADP |
Common Weakness Enumeration