CVE-2023-32191
CVSS V2 None
CVSS V3 None
Description
When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
Overview
- CVE ID
- CVE-2023-32191
- Assigner
- suse
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-16T12:17:02.324Z
- Last Modified Date
- 2024-10-16T15:58:10.698Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-32191 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32191 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-17 13:06:11 | Added to TrackCVE |