First published: Wed May 24 2023(Updated: )
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.
Credit: jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes Minikube | =1.26.0 | |
Kubernetes Minikube | =1.26.1 | |
Kubernetes Minikube | =1.27.0 | |
Kubernetes Minikube | =1.27.1 | |
Kubernetes Minikube | =1.28.0 | |
Apple macOS |
To mitigate these vulnerabilities, upgrade minikube to the latest version and delete any clusters created using an affected version. To delete clusters created using prior versions, run `minikube delete --all`
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1174 is a vulnerability that exposes a network port in minikube running on macOS with Docker driver, potentially enabling unexpected remote access to the minikube container.
CVE-2023-1174 has a severity rating of 9.8 out of 10, making it critical.
Minikube versions 1.26.0, 1.26.1, 1.27.0, 1.27.1, and 1.28.0 are affected by CVE-2023-1174.
No, macOS is not vulnerable to CVE-2023-1174.
To mitigate CVE-2023-1174, it is recommended to update to a version of minikube that is not affected by the vulnerability.