CVE-2023-1944: [minikube] ssh server with default password
Published May 24, 2023
·Updated
This vulnerability enables ssh access to minikube container using a default password.
Affected Software
1 affected component
Kubernetes Minikube<=1.29.0
Remediation
Information
To mitigate these vulnerabilities, upgrade minikube to the latest version and delete any clusters created using an affected version. To delete clusters created using prior versions, run `minikube delete --all`
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-1944?
CVE-2023-1944 is a vulnerability that enables unauthorized ssh access to the minikube container using a default password.
2
How severe is CVE-2023-1944?
CVE-2023-1944 is classified as a high severity vulnerability with a severity value of 7.
3
How does CVE-2023-1944 affect Kubernetes Minikube?
CVE-2023-1944 affects Kubernetes Minikube versions up to and including 1.29.0.
4
How can I fix CVE-2023-1944 vulnerability?
To fix CVE-2023-1944, it is recommended to update Kubernetes Minikube to a version beyond 1.29.0 or apply the necessary security patches.
5
Where can I find more information about CVE-2023-1944?
More information about CVE-2023-1944 can be found at the following link: https://github.com/kubernetes/minikube