SB2023062301 - Privilege escalation in Kubernetes Operations (kOps)



SB2023062301 - Privilege escalation in Kubernetes Operations (kOps)

Published: June 23, 2023

Security Bulletin ID SB2023062301
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Privilege Management (CVE-ID: CVE-2023-1943)

The vulnerability allows a remote user to escalate privileges within the cluster.

The vulnerability exists due to improper privilege management in kOps with the GCP Provider running in Gossip Mode. A remote user can abuse the Node service account credentials, used by a container running in the cluster, to retrieve sensitive information from the state storage bucket and escalate to cluster-admin permissions.


Remediation

Install update from vendor's website.