CVE-2023-32191
16.10.2024, 13:15
When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.Enginsight
Vendor | Product | Version |
---|---|---|
suse | rke | 1.4.19 < 𝑥 < 1.4.19 |
suse | rke | 1.5.10 < 𝑥 < 1.5.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration