FlawAtlas
Search the atlas
CVE-2023-0229 Moderate

Improper input validation in github.com/openshift/apiserver-library-go

Low-privileged users can set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.

Exploit probability 0.6%
Published February 16, 2023
Required by Not available
Last source change May 20, 2024

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/openshift/apiserver-library-go
Go github.com/openshift/apiserver-library-go

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-5465-xc2j-6p84

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.

View original source
Open Source Vulnerabilities GO-2023-1549

Low-privileged users can set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.

View original source

05 / REFERENCES

Further evidence