Github.Com Openshift Apiserver-Library-Go vulnerabilities
2 known vulnerabilities affecting github.com/openshift_apiserver-library-go.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-1260HIGH≥ 0, < 0.0.0-202306212023-09-24
CVE-2023-1260 [HIGH] CWE-288 kube-apiserver authentication bypass vulnerability
kube-apiserver authentication bypass vulnerability
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC a
ghsaosv
CVE-2023-0229MEDIUMCVSS 6.3vopenshift/apiserver-library-go 4.112023-01-26
CVE-2023-0229 [MEDIUM] CWE-20 CVE-2023-0229: A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to d
cvelistv5ghsanvdosv