Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2023/07/06/2 | Mailing List Third Party Advisory | 
| https://github.com/kubernetes/kubernetes/issues/118640 | Issue Tracking | 
| https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 | Mailing List | 
| https://security.netapp.com/advisory/ntap-20230803-0004/ | |
| http://www.openwall.com/lists/oss-security/2023/07/06/2 | Mailing List Third Party Advisory | 
| https://github.com/kubernetes/kubernetes/issues/118640 | Issue Tracking | 
| https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 | Mailing List | 
| https://security.netapp.com/advisory/ntap-20230803-0004/ | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    13 Feb 2025, 17:16
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers. | 
21 Nov 2024, 07:59
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2023/07/06/2 - Mailing List, Third Party Advisory | |
| References | () https://github.com/kubernetes/kubernetes/issues/118640 - Issue Tracking | |
| References | () https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 - Mailing List | |
| References | () https://security.netapp.com/advisory/ntap-20230803-0004/ - | 
12 Jul 2023, 19:12
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| References | (MISC) http://www.openwall.com/lists/oss-security/2023/07/06/2 - Mailing List, Third Party Advisory | |
| References | (MISC) https://github.com/kubernetes/kubernetes/issues/118640 - Issue Tracking | |
| References | (MISC) https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 - Mailing List | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.5 | 
07 Jul 2023, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
03 Jul 2023, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-07-03 21:15
Updated : 2025-02-13 17:16
NVD link : CVE-2023-2727
Mitre link : CVE-2023-2727
CVE.ORG link : CVE-2023-2727
JSON object : View
Products Affected
                kubernetes
- kubernetes
CWE
                