CVE Vulnerabilities

CVE-2023-2727

Published: Jul 03, 2023 | Modified: Aug 03, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.

Affected Software

Name Vendor Start Version End Version
Kubernetes Kubernetes * 1.24.14 (including)
Kubernetes Kubernetes 1.25.0 (including) 1.25.10 (including)
Kubernetes Kubernetes 1.26.0 (including) 1.26.5 (including)
Kubernetes Kubernetes 1.27.0 (including) 1.27.2 (including)

References