Permissions, Privileges, and Access Controls in Kubernetes - CVE-2023-5528

 

Permissions, Privileges, and Access Controls in Kubernetes - CVE-2023-5528

Published: November 20, 2023


Vulnerability identifier: #VU83309
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5528
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions. A remote user with ability to create pods and persistent volumes on Windows nodes can obtain admin privileges on those nodes.

The vulnerability affects Kubernetes clusters only, if they are using an in-tree storage plugin for Windows nodes.


Affected software

Kubernetes
IBM Cloud Pak for Data Scheduling
IBM Concert Software
Gentoo Linux
Fedora
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
ObjectScale
IBM Cloud Pak for Watson AIOps
IBM Netezza for Cloud Pak for Data
OpenShift Container Platform for Windows Containers
kubernetes
sys-cluster/kubelet

How to mitigate CVE-2023-5528

Install updates from vendor's website.

Kubernetes - addressed in versions 1.25.16, 1.26.11, 1.27.8, 1.28.4
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
OpenShift Container Platform for Windows Containers - addressed in versions 6.0.3, 7.2.0, 8.1.1, 9.0.1, 10.15.0
IBM Concert Software - update to 1.0.1
ObjectScale - update to 1.4.0
kubernetes - addressed in versions 1.25.16-1.fc37, 1.26.11-1.fc38, 1.27.8-1.fc39
sys-cluster/kubelet - update to 1.28.5
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3

External References

Related Security Bulletins