Security update for kubernetes1.23
This update for kubernetes1.23 fixes the following issues: - CVE-2021-25743: Escape terminal special characters in kubectl output (bsc#1194400). - CVE-2023-2431: Prevent pods to bypass the seccomp profile enforcement (bsc#1212493). - CVE-2024-0793: Advance autoscaling v2 as the preferred API version (bsc#1219964). - CVE-2024-3177: Prevent bypassing mountable secrets policy imposed by the ServiceAccount admission plugin (bsc#1222539). - CVE-2025-22872: Properly handle trailing solidus in unquoted attribute value in foreign content (bsc#1241865).
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for kubernetes1.23 fixes the following issues: - CVE-2021-25743: Escape terminal special characters in kubectl output (bsc#1194400). - CVE-2023-2431: Prevent pods to bypass the seccomp profile enforcement (bsc#1212493). - CVE-2024-0793: Advance autoscaling v2 as the preferred API version (bsc#1219964). - CVE-2024-3177: Prevent bypassing mountable secrets policy imposed by the ServiceAccount admission plugin (bsc#1222539). - CVE-2025-22872: Properly handle trailing solidus in unquoted attribute value in foreign content (bsc#1241865).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1194400
- https://bugzilla.suse.com/1212493
- https://bugzilla.suse.com/1219964
- https://bugzilla.suse.com/1222539
- https://bugzilla.suse.com/1229008
- https://bugzilla.suse.com/1241865
- https://www.suse.com/security/cve/CVE-2021-25743
- https://www.suse.com/security/cve/CVE-2023-2431
- https://www.suse.com/security/cve/CVE-2024-0793
- https://www.suse.com/security/cve/CVE-2024-3177
- https://www.suse.com/security/cve/CVE-2025-22872
- https://www.suse.com/support/update/announcement/2025/suse-su-202502423-1/