CVE-2023-3676: Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-3676?
CVE-2023-3676 is a vulnerability in Kubernetes that allows a user with the ability to create pods on Windows nodes to escalate to admin privileges on those nodes.
How does CVE-2023-3676 impact Kubernetes clusters?
CVE-2023-3676 only affects Kubernetes clusters that include Windows nodes.
What is the severity of CVE-2023-3676?
CVE-2023-3676 has a severity rating of 8.8 (High).
How can I fix CVE-2023-3676?
To fix CVE-2023-3676, it is recommended to update Kubernetes to a version that includes the necessary security patches.
Where can I find more information about CVE-2023-3676?
You can find more information about CVE-2023-3676 in the following references: 1. [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:4777) 2. [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:4780) 3. [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:4835)