Closed
Description
In GitHub Security Advisory GHSA-7fxm-f474-hf8w, there is a vulnerability in the following Go packages or modules:
Unit | Fixed | Vulnerable Ranges |
---|---|---|
k8s.io/kubernetes | 1.24.17 | < 1.24.17 |
Cross references:
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-qh36-44jv-c8xj #617 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes/pkg/apiserver: GHSA-pmqp-h87c-mr78 #703 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes/pkg/util/mount: GHSA-wqwf-x5cj-rg56 #886 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: CVE-2020-8561, GHSA-74j8-88mm-7496 #904 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: CVE-2021-25735, GHSA-g42g-737j-qx6j #907 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: CVE-2021-25737, GHSA-mfv7-gq43-w965 #908 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: CVE-2021-25740, GHSA-vw47-mr44-3jf9 #909 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: CVE-2021-25741, GHSA-f5f7-6478-qm6p #910 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: CVE-2020-8554, GHSA-j9wf-vvm6-4r9w #940 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes/pkg/kubectl: CVE-2021-25743, GHSA-f9jg-8p32-2f55 #983 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-2jx2-76rc-2v7v #1492 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-xc8m-28vv-4pjc #1864 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-qc2g-gmh6-95p4 #1891 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-cgcv-5272-97pr #1892 NOT_IMPORTABLE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-f4w6-3rh6-6q4q #1943 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-q4rr-64r9-fwgf #1946 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-2jq6-ffph-p4h8 #1959 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-mm7g-f2gg-cw8g #1977 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-2h9c-34v6-3qmr #1985 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in k8s.io/kubernetes: GHSA-q78c-gwqw-jcmc #2170 EFFECTIVELY_PRIVATE
- Module k8s.io/kubernetes appears in issue dummy issue #64
- Module k8s.io/kubernetes appears in issue dummy issue #65
- Module k8s.io/kubernetes appears in issue dummy issue #66
- Module k8s.io/kubernetes appears in issue x/vulndb: potential Go vuln in github.com/kubernetes/kubernetes: GHSA-jp32-vmm6-3vf5 #701
See doc/triage.md for instructions on how to triage this report.
modules:
- module: k8s.io/kubernetes
versions:
- fixed: 1.24.17
vulnerable_at: 1.24.16
packages:
- package: k8s.io/kubernetes
- module: k8s.io/kubernetes
versions:
- introduced: 1.25.0
fixed: 1.25.13
vulnerable_at: 1.25.12
packages:
- package: k8s.io/kubernetes
- module: k8s.io/kubernetes
versions:
- introduced: 1.26.0
fixed: 1.26.8
vulnerable_at: 1.26.7
packages:
- package: k8s.io/kubernetes
- module: k8s.io/kubernetes
versions:
- introduced: 1.27.0
fixed: 1.27.5
vulnerable_at: 1.27.4
packages:
- package: k8s.io/kubernetes
- module: k8s.io/kubernetes
versions:
- introduced: TODO (earliest fixed "1.28.1", vuln range "= 1.28.0")
packages:
- package: k8s.io/kubernetes
summary: Kubernetes privilege escalation vulnerability
cves:
- CVE-2023-3676
ghsas:
- GHSA-7fxm-f474-hf8w
references:
- web: https://nvd.nist.gov/vuln/detail/CVE-2023-3676
- report: https://github.com/kubernetes/kubernetes/issues/119339
- web: https://groups.google.com/g/kubernetes-security-announce/c/d_fvHZ9a5zc
- fix: https://github.com/kubernetes/kubernetes/pull/120127
- fix: https://github.com/kubernetes/kubernetes/pull/120129
- fix: https://github.com/kubernetes/kubernetes/pull/120130
- fix: https://github.com/kubernetes/kubernetes/pull/120131
- fix: https://github.com/kubernetes/kubernetes/pull/120132
- fix: https://github.com/kubernetes/kubernetes/pull/120133
- fix: https://github.com/kubernetes/kubernetes/commit/073f9ea33a93ddaecdc2e829150fb715f6387399
- fix: https://github.com/kubernetes/kubernetes/commit/39cc101c7855341c651a943b9836b50fbace8a6b
- fix: https://github.com/kubernetes/kubernetes/commit/74b617310c24ca84c2ec90c3858af745d65b5226
- fix: https://github.com/kubernetes/kubernetes/commit/890483394221c8f22e88c48f86cd4eaf4de65fd6
- fix: https://github.com/kubernetes/kubernetes/commit/a53faf5e17ed0b0771a605c6401ba4cbf297b59a
- advisory: https://github.com/advisories/GHSA-7fxm-f474-hf8w