First published: Wed Oct 11 2023(Updated: )
Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
Credit: jordan@liggitt.net jordan@liggitt.net jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes Operations | <1.25.4 | |
Kubernetes Operations | >=1.26.0<1.26.2 | |
go/k8s.io/kops | >=1.26.0<1.26.2 | 1.26.2 |
go/k8s.io/kops | <1.25.4 | 1.25.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1943 is a privilege escalation vulnerability in kOps using GCE/GCP Provider in Gossip Mode.
CVE-2023-1943 affects Kubernetes Operations version 1.25.4 up to exclusive version 1.26.2.
CVE-2023-1943 is rated as high severity with a severity score of 8.
To fix CVE-2023-1943, update Kubernetes Operations to version 1.26.2 or apply the recommended remedy package for k8s.io/kops version 1.26.2.
You can find more information about CVE-2023-1943 in the following references: [GitHub Issue](https://github.com/kubernetes/kops/issues/15539), [Google Groups](https://groups.google.com/g/kubernetes-security-announce/c/yrCE1x89oaU), [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-1943).