CVE Vulnerabilities

CVE-2023-0229

Published: Jan 26, 2023 | Modified: Feb 06, 2023
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to unconfined. By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is runtime/default, allowing users to disable seccomp for pods they can create and modify.

Affected Software

Name Vendor Start Version End Version
Openshift Redhat 4.11 (including) 4.11 (including)
Openshift Redhat 4.12 (including) 4.12 (including)

References