CVE-2023-5408 is a high-severity privilege escalation flaw affecting the node restriction admission plugin in the Kubernetes API server of Red Hat OpenShift Container Platform. An authenticated remote attacker, by modifying the node role label, could redirect workloads from control plane and etcd nodes to worker nodes, thereby gaining broader cluster access. With a CVSS score of 7.2, this vulnerability has a high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:* | ||
4.12CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* | ||
4.13CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:* | ||
4.14CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.