#VU77653 Improper Privilege Management in Kubernetes Operations (kOps) - CVE-2023-1943
Published: June 23, 2023
Kubernetes Operations (kOps)
Kubernetes
Description
The vulnerability allows a remote user to escalate privileges within the cluster.
The vulnerability exists due to improper privilege management in kOps with the GCP Provider running in Gossip Mode. A remote user can abuse the Node service account credentials, used by a container running in the cluster, to retrieve sensitive information from the state storage bucket and escalate to cluster-admin permissions.