CVE-2023-2728

CVE Details

Release Date:2023-07-03

Description


Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account's secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with ephemeral containers.

See more information about CVE-2023-2728 from MITRE CVE dictionary and NIST NVD


CVSS v3.0 metrics


NOTE: The following CVSS v3.0 metrics and score provided are preliminary and subject to review.

Base Score: 6.5 Base Metrics: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Access Vector: Network Attack Complexity: Low
Privileges Required: High User Interaction: None
Scope: Unchanged Confidentiality Impact: High
Integrity Impact: High Availability Impact: None

Errata information


PlatformErrataRelease Date
Oracle Linux version 7 (kubernetes)ELSA-2023-125622023-07-03
Oracle Linux version 7 (kubernetes)ELSA-2023-125632023-07-03
Oracle Linux version 7 (olcne)ELSA-2023-125622023-07-03
Oracle Linux version 7 (olcne)ELSA-2023-125632023-07-03
Oracle Linux version 7 (olcne)ELSA-2023-255452023-07-03
Oracle Linux version 7 (yq)ELSA-2023-125632023-07-03
Oracle Linux version 8 (kubernetes)ELSA-2023-125612023-07-03
Oracle Linux version 8 (kubernetes)ELSA-2023-125642023-07-03
Oracle Linux version 8 (olcne)ELSA-2023-125612023-07-03
Oracle Linux version 8 (olcne)ELSA-2023-125642023-07-03
Oracle Linux version 8 (olcne)ELSA-2023-255462023-07-03
Oracle Linux version 8 (yq)ELSA-2023-125642023-07-03



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete