Vulnerability Report: GO-2023-2170
- CVE-2023-3955, GHSA-q78c-gwqw-jcmc
- Affects: k8s.io/kubernetes, k8s.io/mount-utils
- Published: Aug 21, 2024
- Modified: Dec 12, 2024
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-q78c-gwqw-jcmc.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.24.17, from v1.25.0 before v1.25.13, from v1.26.0 before v1.26.8, from v1.27.0 before v1.27.5, from v1.28.0 before v1.28.1
-
before v0.24.17, from v0.25.0 before v0.25.13, from v0.26.0 before v0.26.8, from v0.27.0 before v0.27.5, from v0.28.0 before v0.28.1
2 unexported affected symbols
- SafeFormatAndMount.formatAndMountSensitive
- listVolumesOnDisk
Aliases
References
- https://github.com/advisories/GHSA-q78c-gwqw-jcmc
- https://github.com/kubernetes/kubernetes/commit/38c97fa67ed35f36e730856728c9e3807f63546a
- https://github.com/kubernetes/kubernetes/commit/50334505cd27cbe7cf71865388f25a00e29b2596
- https://github.com/kubernetes/kubernetes/commit/7da6d72c05dffb3b87e62e2bc8c3228ea12ba1b9
- https://github.com/kubernetes/kubernetes/commit/b7547e28f898af37aa2f1107a49111f963250fe6
- https://github.com/kubernetes/kubernetes/commit/c4e17abb04728e3a3f9bb26e727b0f978df20ec9
- https://github.com/kubernetes/kubernetes/issues/119595
- https://github.com/kubernetes/kubernetes/pull/120128
- https://github.com/kubernetes/kubernetes/pull/120134
- https://github.com/kubernetes/kubernetes/pull/120135
- https://github.com/kubernetes/kubernetes/pull/120136
- https://github.com/kubernetes/kubernetes/pull/120137
- https://github.com/kubernetes/kubernetes/pull/120138
- https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E
- https://vuln.go.dev/ID/GO-2023-2170.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.