cbcvebase.
CVE-2023-0229
published 2023-01-26

CVE-2023-0229: A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to…

PriorityP336medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.65%
47.3th percentile
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.

Affected

15 ranges
VendorProductVersion rangeFixed in
github.comopenshift_apiserver-library-go
github.comopenshift_apiserver-library-go>= 0 < 0.0.0-20230119093715-30f75d79e4240.0.0-20230119093715-30f75d79e424
github.comopenshift_apiserver-library-go>= 0 < 0.0.0-20230120221150-cefee9e0162b0.0.0-20230120221150-cefee9e0162b
redhatopenshift
redhatopenshift
x.orgxorg-server>= 0 < 2:1.20.13-1ubuntu1~20.04.152:1.20.13-1ubuntu1~20.04.15
x.orgxorg-server>= 0 < 2:1.20.13-1ubuntu1~20.04.142:1.20.13-1ubuntu1~20.04.14
x.orgxorg-server>= 0 < 2:21.1.4-2ubuntu1.7~22.04.82:21.1.4-2ubuntu1.7~22.04.8
x.orgxorg-server>= 0 < 2:21.1.4-2ubuntu1.7~22.04.72:21.1.4-2ubuntu1.7~22.04.7
x.orgxorg-server>= 0 < 2:1.18.4-0ubuntu0.12+esm92:1.18.4-0ubuntu0.12+esm9
x.orgxorg-server>= 0 < 2:1.18.4-0ubuntu0.12+esm102:1.18.4-0ubuntu0.12+esm10
x.orgxorg-server>= 0 < 2:1.19.6-1ubuntu4.15+esm42:1.19.6-1ubuntu4.15+esm4
x.orgxorg-server>= 0 < 2:1.19.6-1ubuntu4.15+esm52:1.19.6-1ubuntu4.15+esm5
x.orgxwayland>= 0 < 2:22.1.1-1ubuntu0.112:22.1.1-1ubuntu0.11
x.orgxwayland>= 0 < 2:22.1.1-1ubuntu0.102:22.1.1-1ubuntu0.10

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv9.8CRITICAL
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.