Database/Container, Kubernetes & orchestration
Kubernetes: Command injection via pod spec on Windows nodes
CVSS 8.8CVE-2023-3676Container, Kubernetes & orchestrationcurated
Impact
Command injection via pod spec on Windows nodes; escalation to node admin
Who can reach it
Cluster user able to create pods on a Windows node
What to do
Rolling control-plane and kubelet upgrade; Windows node drain
References
Related entries
- Kubernetes: Second Windows-node input-sanitisation escalation to adminCVE-2023-3955 · KubernetesHigh
- Kubernetes: Malformed docker config leaks registry pull secrets into logsCVE-2020-8564 · KubernetesMedium
- Kubernetes: Authorization and bearer tokens written to logs at verbosity 9CVE-2020-8565 · KubernetesMedium
- Kubernetes: Endpoint/EndpointSlice confused-deputy lets users reach networks they should notCVE-2021-25740 · KubernetesLow
- Kubernetes: Endpoint IPs can redirect pod traffic to private node networksCVE-2021-25737 · KubernetesLow
- kubernetes-csi-proxy: Insufficient input sanitisation in csi-proxy leads to Windows node adminCVE-2023-3893 · kubernetes-csi-proxyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.