Openshift: modification of node role labels
Vulnerability Description
A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-5408
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was discovered by Derek Carr (Red Hat) and Mrunal Patel (Red Hat).
References
- https://access.redhat.com/errata/RHSA-2023:5006
- https://access.redhat.com/errata/RHSA-2023:6130
- https://access.redhat.com/errata/RHSA-2023:6842
- https://access.redhat.com/errata/RHSA-2023:7479
- https://access.redhat.com/security/cve/CVE-2023-5408
- https://bugzilla.redhat.com/show_bug.cgi?id=2242173
- https://github.com/openshift/kubernetes/pull/1736
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →