Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2023/07/06/2 | Mailing List Third Party Advisory |
https://github.com/kubernetes/kubernetes/issues/118640 | Issue Tracking |
https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 | Mailing List |
https://security.netapp.com/advisory/ntap-20230803-0004/ | |
http://www.openwall.com/lists/oss-security/2023/07/06/2 | Mailing List Third Party Advisory |
https://github.com/kubernetes/kubernetes/issues/118640 | Issue Tracking |
https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 | Mailing List |
https://security.netapp.com/advisory/ntap-20230803-0004/ |
Configurations
Configuration 1 (hide)
|
History
13 Feb 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers. |
21 Nov 2024, 07:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2023/07/06/2 - Mailing List, Third Party Advisory | |
References | () https://github.com/kubernetes/kubernetes/issues/118640 - Issue Tracking | |
References | () https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 - Mailing List | |
References | () https://security.netapp.com/advisory/ntap-20230803-0004/ - |
12 Jul 2023, 19:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
References | (MISC) http://www.openwall.com/lists/oss-security/2023/07/06/2 - Mailing List, Third Party Advisory | |
References | (MISC) https://github.com/kubernetes/kubernetes/issues/118640 - Issue Tracking | |
References | (MISC) https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8 - Mailing List | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
07 Jul 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 Jul 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-03 21:15
Updated : 2025-02-13 17:16
NVD link : CVE-2023-2727
Mitre link : CVE-2023-2727
CVE.ORG link : CVE-2023-2727
JSON object : View
Products Affected
kubernetes
- kubernetes
CWE