blob: 350b7dd365e1ffe37285e09236772ce7169f8cd6 [file] [log] [blame]
id: GO-2023-1864
modules:
- module: k8s.io/kubernetes
versions:
- fixed: 1.24.14
- introduced: 1.25.0
- fixed: 1.25.10
- introduced: 1.26.0
- fixed: 1.26.5
- introduced: 1.27.0
- fixed: 1.27.2
vulnerable_at: 1.27.1
summary: Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes
cves:
- CVE-2023-2431
ghsas:
- GHSA-xc8m-28vv-4pjc
references:
- advisory: https://github.com/advisories/GHSA-xc8m-28vv-4pjc
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-2431
- web: https://github.com/kubernetes/kubernetes/issues/118690
- web: https://github.com/kubernetes/kubernetes/pull/117020
- web: https://github.com/kubernetes/kubernetes/pull/117116
- web: https://github.com/kubernetes/kubernetes/pull/117117
- web: https://github.com/kubernetes/kubernetes/pull/117118
- web: https://github.com/kubernetes/kubernetes/pull/117147
- web: https://groups.google.com/g/kubernetes-security-announce/c/QHmx0HOQa10
- web: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/43HDSKBKPSW53OW647B5ETHRWFFNHSRQ
- web: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBX4RL4UOC7JHWWYB2AJCKSUM7EG5Y5G
source:
id: GHSA-xc8m-28vv-4pjc
created: 2024-08-20T11:49:15.50631-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE