CVE-2023-1943: Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode
Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1943?
CVE-2023-1943 is a privilege escalation vulnerability in kOps using GCE/GCP Provider in Gossip Mode.
How does CVE-2023-1943 impact Kubernetes Operations?
CVE-2023-1943 affects Kubernetes Operations version 1.25.4 up to exclusive version 1.26.2.
What is the severity of CVE-2023-1943?
CVE-2023-1943 is rated as high severity with a severity score of 8.
How can I fix CVE-2023-1943?
To fix CVE-2023-1943, update Kubernetes Operations to version 1.26.2 or apply the recommended remedy package for k8s.io/kops version 1.26.2.
Where can I find more information about CVE-2023-1943?
You can find more information about CVE-2023-1943 in the following references: [GitHub Issue](https://github.com/kubernetes/kops/issues/15539), [Google Groups](https://groups.google.com/g/kubernetes-security-announce/c/yrCE1x89oaU), [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-1943).