GHSA-fp37-c92q-4pwq

    Dashboard / Vulnerabilities / GHSA-fp37-c92q-4pwq

    GHSA-fp37-c92q-4pwq

    Published: 24 May 2022Last Modified: 8 Nov 2023

    Summary: Kubernetes kube-apiserver unauthorized access

    Details: The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a resource in one namespace could create, view update or delete the cluster-scoped resource (according to their namespace role privileges). Kubernetes affected versions include versions prior to 1.13.9, versions prior to 1.14.5, versions prior to 1.15.2, and versions 1.7, 1.8, 1.9, 1.10, 1.11, 1.12.

    Affected packages

    Package

    Name: k8s.io/apiextensions-apiserver

    Purl: pkg:golang/k8s.io/apiextensions-apiserver

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.7.0
    Fixed -0.13.9

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-fp37-c92q-4pwq | CVE-DB