CVE-2023-3893: Kubernetes - csi-proxy - Insufficient input sanitization leads to privilege escalation
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.
Other sources
Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3893?
CVE-2023-3893 is a vulnerability in Kubernetes where a user can escalate to admin privileges on Windows nodes running kubernetes-csi-proxy.
How does CVE-2023-3893 affect Kubernetes clusters?
Kubernetes clusters are affected if they include Windows nodes running kubernetes-csi-proxy.
What is the severity of CVE-2023-3893?
The severity of CVE-2023-3893 is high, with a severity value of 8.8.
How can I fix CVE-2023-3893?
To fix CVE-2023-3893, upgrade to kubernetes-csi-proxy version 1.1.3 or 2.0.0-alpha.1, depending on the affected version.
Where can I find more information about CVE-2023-3893?
You can find more information about CVE-2023-3893 at the following references: - [GitHub Issue](https://github.com/kubernetes/kubernetes/issues/119594) - [Google Groups Announcement](https://groups.google.com/g/kubernetes-security-announce/c/lWksE2BoCyQ) - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-3893)