Input validation error in Kubernetes - CVE-2023-3676

 

Input validation error in Kubernetes - CVE-2023-3676

Published: August 25, 2023


Vulnerability identifier: #VU80006
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3676
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on Windows nodes.

The vulnerability exists due to improper input validation. A remote user with ability to create pods on Windows nodes can obtain administrative privileges on these nodes.


Affected software

Kubernetes
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
Windows Container Support for Red Hat OpenShift
OpenShift Container Platform for Windows Containers
Fedora
kubernetes
Cloud Pak for Data

How to mitigate CVE-2023-3676

Install updates from vendor's website.

Kubernetes - addressed in versions 1.24.17, 1.25.13, 1.26.8, 1.27.5, 1.28.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Windows Container Support for Red Hat OpenShift - addressed in versions 5.1.2, 6.0.2, 7.1.1, 8.0.2
kubernetes - addressed in versions 1.26.8-1.fc38, 1.27.5-1.fc39
IBM Cloud Pak for Watson AIOps - update to 4.8.1
Cloud Pak for Data - update to 4.8.5
OpenShift Container Platform for Windows Containers - update to 9.0.0

External References

Related Security Bulletins