GPU VulnDB

Database/Container, Kubernetes & orchestration

Kubernetes (kube-apiserver): Users authorized to list/watch one namespaced CR type can read other CR types in the same

CVE-2022-3162Container, Kubernetes & orchestrationcurated

Impact

Users authorized to list/watch one namespaced CR type can read other CR types in the same API group cluster-wide; cross-tenant data exposure

Who can reach it

Cluster user with namespace access

What to do

Rolling control-plane upgrade; no GPU drain. Audit CRD RBAC

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.