GHSA-33c5-9fx5-fvjm

    Dashboard / Vulnerabilities / GHSA-33c5-9fx5-fvjm

    GHSA-33c5-9fx5-fvjm

    Published: 24 Apr 2024Last Modified: 10 Sept 2026

    Summary: Privilege Escalation in Kubernetes

    Details: The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.7 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

    Affected packages

    Package

    Name: k8s.io/apimachinery

    Purl: pkg:golang/k8s.io/apimachinery

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.16.13

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-33c5-9fx5-fvjm | CVE-DB