← Back to CVE List

CVE-2023-1260

Published: 2023-09-24T01:15Z
Last Modified: 2024-11-21T07:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt