Bypassing policies imposed by the ImagePolicyWebhook admission plugin
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
02 / AFFECTED SOFTWARE
Affected packages
197 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2023/07/06/2
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2727.json
- https://github.com/kubernetes/kubernetes/issues/118640
- https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8
- https://nvd.nist.gov/vuln/detail/CVE-2023-2727
- https://security.netapp.com/advisory/ntap-20230803-0004/
- https://github.com/advisories/GHSA-qc2g-gmh6-95p4
- https://github.com/kubernetes/kubernetes/pull/118356
- https://github.com/kubernetes/kubernetes/pull/118471
- https://github.com/kubernetes/kubernetes/pull/118473
- https://github.com/kubernetes/kubernetes/pull/118474
- https://github.com/kubernetes/kubernetes/pull/118512
- https://github.com/kubernetes/kubernetes
- https://security.netapp.com/advisory/ntap-20230803-0004