CVE-2023-1260
published 2023-09-24CVE-2023-1260: An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions…
PriorityP349high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
EPSS
1.57%
72.6th percentile
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | openshift_apiserver-library-go | >= 0 < 0.0.0-20230621 | 0.0.0-20230621 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kube-apiserver: PrivEsc
vendor_redhat·2023-04-04·CVSS 8.0
CVE-2023-1260 [HIGH] CWE-288 kube-apiserver: PrivEsc
kube-apiserver: PrivEsc
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. Thi
OSV
kube-apiserver authentication bypass vulnerability
osv·2023-09-24
CVE-2023-1260 [HIGH] kube-apiserver authentication bypass vulnerability
kube-apiserver authentication bypass vulnerability
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.
GHSA
kube-apiserver authentication bypass vulnerability
ghsa·2023-09-24
CVE-2023-1260 [HIGH] CWE-288 kube-apiserver authentication bypass vulnerability
kube-apiserver authentication bypass vulnerability
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:3976https://access.redhat.com/errata/RHSA-2023:4093https://access.redhat.com/errata/RHSA-2023:4312https://access.redhat.com/errata/RHSA-2023:4898https://access.redhat.com/errata/RHSA-2023:5008https://access.redhat.com/security/cve/CVE-2023-1260https://bugzilla.redhat.com/show_bug.cgi?id=2176267https://github.com/advisories/GHSA-92hx-3mh6-hc49https://security.netapp.com/advisory/ntap-20231020-0010/https://access.redhat.com/errata/RHSA-2023:3976https://access.redhat.com/errata/RHSA-2023:4093https://access.redhat.com/errata/RHSA-2023:4312https://access.redhat.com/errata/RHSA-2023:4898https://access.redhat.com/errata/RHSA-2023:5008https://access.redhat.com/security/cve/CVE-2023-1260https://bugzilla.redhat.com/show_bug.cgi?id=2176267https://github.com/advisories/GHSA-92hx-3mh6-hc49https://security.netapp.com/advisory/ntap-20231020-0010/
2023-09-24
Published