Permissions, Privileges, and Access Controls in Kubernetes - CVE-2023-5528
Published: November 20, 2023
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions. A remote user with ability to create pods and persistent volumes on Windows nodes can obtain admin privileges on those nodes.
The vulnerability affects Kubernetes clusters only, if they are using an in-tree storage plugin for Windows nodes.
Affected software
IBM Cloud Pak for Data Scheduling
IBM Concert Software
Gentoo Linux
Fedora
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
ObjectScale
IBM Cloud Pak for Watson AIOps
IBM Netezza for Cloud Pak for Data
OpenShift Container Platform for Windows Containers
kubernetes
sys-cluster/kubelet
How to mitigate CVE-2023-5528
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
OpenShift Container Platform for Windows Containers - addressed in versions 6.0.3, 7.2.0, 8.1.1, 9.0.1, 10.15.0
IBM Concert Software - update to 1.0.1
ObjectScale - update to 1.4.0
kubernetes - addressed in versions 1.25.16-1.fc37, 1.26.11-1.fc38, 1.27.8-1.fc39
sys-cluster/kubelet - update to 1.28.5
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
External References
Related Security Bulletins
- Privilege escalation in Kubernetes
- Fedora 37 update for kubernetes
- Fedora 39 update for kubernetes
- Fedora 38 update for kubernetes
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 6.0
- Red Hat OpenShift for Windows Containers 8.1 update for kubernetes
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 7.2
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 10.15
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 9.0
- Permissions, privileges, and access controls in IBM Cloud Pak for Data Scheduling
- Gentoo update for Kubelet
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data