Vulnerability CVE-2023-1260


Published: 2023-09-24

Description:
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.

 References:
https://access.redhat.com/security/cve/CVE-2023-1260
https://bugzilla.redhat.com/show_bug.cgi?id=2176267
https://access.redhat.com/errata/RHSA-2023:4312
https://access.redhat.com/errata/RHSA-2023:4093
https://access.redhat.com/errata/RHSA-2023:3976
https://access.redhat.com/errata/RHSA-2023:4898

Copyright 2026, cxsecurity.com

 

Back to Top