Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-2431

17
FAUCET Score

CVE-2023-2431 describes a security flaw in Kubelet that permits Kubernetes pods to bypass seccomp profile enforcement. Specifically, pods configured with a localhost seccomp profile but an empty profile field can execute in an unconfined mode, effectively disabling seccomp. This vulnerability impacts various Kubernetes distributions, including those from fedoraproject. Rated as MEDIUM severity with a CVSS score of 5.5, this vulnerability has a low attack complexity and requires local privileges to exploit. The primary impact is a high integrity loss, as it allows unauthorized actions within the affected pod, though confidentiality and availability are not directly impacted. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.24.14CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.25.0, < 1.25.10CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.26.0, < 1.26.5CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.27.0, < 1.27.2CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 71st percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.25.10
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.26.5
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.27.2
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.24.14
infiniflowpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: openshift4-wincw/windows-machine-config-rhel9-operator:8.1.0-24
View patch
vuepatch availablevia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argo-rollouts-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-agent
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: io.fabric8:kubernetes-model
redhatvendor investigatingvia redhat_api
Product: OpenShift API for Data ProtectionFixed in: oadp/oadp-velero-plugin-for-microsoft-azure-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/gitops-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-scanner-rhel8
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-multicluster-rhel9-operator

Vendor Advisories (6)

goGHSA-xc8m-28vv-4pjcmedium

Kubelet vulnerable to bypass of seccomp profile enforcement

Jun 16, 2023
redhatCVE-2023-2431Low

kubernetes: Bypass of seccomp profile enforcement

Jun 16, 2023
vuellm-vue-eca8aa61073a0ba1

Bypass of seccomp profile enforcement

chromellm-chrome-842b49157590565a

Bypass of seccomp profile enforcement

check_pointllm-check_point-036f2cee613660c6

Bypass of seccomp profile enforcement

infiniflowllm-infiniflow-d2d2623665df58ad

Bypass of seccomp profile enforcement

References

github.com / kubernetes/kubernetes/issues/118690
Issue Tracking
groups.google.com / g/kubernetes-security-announce/c/QHmx0HOQa10
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/43HDSKBKPSW53OW647B5ETHRWFFNHSRQ
lists.fedoraproject.org / archives/list/[email protected]/message/XBX4RL4UOC7JHWWYB2AJCKSUM7EG5Y5G
Mailing List