Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-07-03 21:15
Updated : 2023-08-03 15:15
NVD link : CVE-2023-2728
Mitre link : CVE-2023-2728
CVE.ORG link : CVE-2023-2728
JSON object : View
Products Affected
kubernetes
- kubernetes
CWE