SB2023062301 - Privilege escalation in Kubernetes Operations (kOps)
Published: June 23, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Privilege Management (CVE-ID: CVE-2023-1943)
The vulnerability allows a remote user to escalate privileges within the cluster.
The vulnerability exists due to improper privilege management in kOps with the GCP Provider running in Gossip Mode. A remote user can abuse the Node service account credentials, used by a container running in the cluster, to retrieve sensitive information from the state storage bucket and escalate to cluster-admin permissions.
Remediation
Install update from vendor's website.