Improper Handling of Insufficient Privileges Affecting k8s.io/kops package, versions <1.25.4>=1.26.0 <1.26.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-K8SIOKOPS-5734630
  • published23 Jun 2023
  • disclosed21 Jun 2023
  • creditJames Cleverley-Prance

Introduced: 21 Jun 2023

CVE-2023-1943  (opens in a new tab)
CWE-274  (opens in a new tab)

How to fix?

Upgrade k8s.io/kops to version 1.25.4, 1.26.2 or higher.

Overview

k8s.io/kops is a package that helps you create, destroy, upgrade and maintain production-grade, highly available, Kubernetes clusters from the command line.

Affected versions of this package are vulnerable to Improper Handling of Insufficient Privileges when the GCP Provider is running in Gossip Mode. Node service account credentials could be used by a container running in the cluster to retrieve sensitive information from the state storage bucket and escalate to cluster-admin permissions.

CVSS Scores

version 3.1