CVE-2023-1174: [minikube] Network Port exposure in minikube running on macOS using Docker driver
Published May 24, 2023
·Updated
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.
Affected Software
6 affected components
Kubernetes Minikube=1.26.0
Kubernetes Minikube=1.26.1
Kubernetes Minikube=1.27.0
Kubernetes Minikube=1.27.1
Kubernetes Minikube=1.28.0
Apple macOS
Remediation
Information
To mitigate these vulnerabilities, upgrade minikube to the latest version and delete any clusters created using an affected version. To delete clusters created using prior versions, run `minikube delete --all`
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-1174?
CVE-2023-1174 is a vulnerability that exposes a network port in minikube running on macOS with Docker driver, potentially enabling unexpected remote access to the minikube container.
2
What is the severity of CVE-2023-1174?
CVE-2023-1174 has a severity rating of 9.8 out of 10, making it critical.
3
Which version of minikube is affected by CVE-2023-1174?
Minikube versions 1.26.0, 1.26.1, 1.27.0, 1.27.1, and 1.28.0 are affected by CVE-2023-1174.
4
Is macOS vulnerable to CVE-2023-1174?
No, macOS is not vulnerable to CVE-2023-1174.
5
How can I mitigate CVE-2023-1174?
To mitigate CVE-2023-1174, it is recommended to update to a version of minikube that is not affected by the vulnerability.