A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| k8s.io/kubernetes(Go) | 1.28.0 | 1.28.1 | N/A |
| k8s.io/kubernetes(Go) | 1.27.0 | 1.27.5 | N/A |
| k8s.io/kubernetes(Go) | 1.26.0 | 1.26.8 | N/A |
| k8s.io/kubernetes(Go) | 1.25.0 | 1.25.13 | N/A |
| k8s.io/kubernetes(Go) | 0 | 1.24.17 | N/A |
CVSS Metrics