A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
References
| Link | Resource |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/119595 | Exploit Mitigation Patch Third Party Advisory |
| https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E | Technical Description |
| https://security.netapp.com/advisory/ntap-20231221-0002/ | |
| https://github.com/kubernetes/kubernetes/issues/119595 | Exploit Mitigation Patch Third Party Advisory |
| https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E | Technical Description |
| https://security.netapp.com/advisory/ntap-20231221-0002/ |
Configurations
Configuration 1 (hide)
| AND |
|
History
13 Feb 2025, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. |
Information
Published : 2023-10-31 21:15
Updated : 2025-02-13 17:17
NVD link : CVE-2023-3955
Mitre link : CVE-2023-3955
CVE.ORG link : CVE-2023-3955
JSON object : View
Products Affected
microsoft
- windows
kubernetes
- kubernetes
CWE
CWE-20
Improper Input Validation
