Improper Input Validation Affecting github.com/kubernetes/kubernetes/pkg/volume/util/subpath package, versions <1.24.17>=1.25.0 <1.25.13>=1.26.0 <1.26.8>=1.27.0 <1.27.5>=1.28.0 <1.28.1


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.11% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMKUBERNETESKUBERNETESPKGVOLUMEUTILSUBPATH-5862742
  • published28 Aug 2023
  • disclosed23 Aug 2023
  • creditTomer Peled

Introduced: 23 Aug 2023

CVE-2023-3676  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade github.com/kubernetes/kubernetes/pkg/volume/util/subpath to version 1.24.17, 1.25.13, 1.26.8, 1.27.5, 1.28.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation allows a user who can create pods on Windows nodes to get admin privileges on those nodes.

Note Kubernetes clusters are only affected if they include Windows nodes.

CVSS Scores

version 3.1