CVE-2023-3893 describes a privilege escalation vulnerability in Kubernetes affecting Windows nodes running kubernetes-csi-proxy. An authenticated user with pod creation privileges on these specific nodes can escalate to administrative access. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity and significant impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered notable community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.2CPE matchmatch criteria | cpe:2.3:a:kubernetes:csi_proxy:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:kubernetes:csi_proxy:2.0.0:alpha0:*:*:*:*:*:* | ||
>= 0, <= v1.1.2CPE match | cpe:2.3:a:kubernetes:csi_proxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation
Nov 3, 2023kubernetes: Insufficient input sanitization on kubernetes CSI proxy leads to privilege escalation
Aug 23, 2023Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation