CVE-2023-5408

high

Description

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.

References

https://www.ibm.com/support/pages/node/7114006

https://github.com/openshift/kubernetes/pull/1736

https://bugzilla.redhat.com/show_bug.cgi?id=2242173

https://access.redhat.com/security/cve/CVE-2023-5408

https://access.redhat.com/errata/RHSA-2023:7479

https://access.redhat.com/errata/RHSA-2023:6842

https://access.redhat.com/errata/RHSA-2023:6130

https://access.redhat.com/errata/RHSA-2023:5006

Details

Source: Mitre, NVD

Published: 2023-11-02

Updated: 2024-01-21

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High