Total vulnerabilities in the database
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.
Software | From | Fixed in |
---|---|---|
![]() |
- | 0.0.0-20230621 |
redhat / openshift_container_platform | 4.10 | 4.10.x |
redhat / openshift_container_platform | 4.12 | 4.12.x |
redhat / openshift_container_platform | 4.11 | 4.11.x |
redhat / openshift_container_platform | 4.13 | 4.13.x |