CVE-2023-3955

Source
https://cve.org/CVERecord?id=CVE-2023-3955
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-3955.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-3955
Aliases
Downstream
Related
Published
2023-10-31T20:36:54.352Z
Modified
2026-05-18T05:56:42.417951049Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
Details

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "cna_assigner": "kubernetes",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3955.json"
}
References

Affected packages

Git / github.com/kubernetes/kubelet

Affected ranges

Type
GIT
Repo
https://github.com/kubernetes/kubelet
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.24.17"
        },
        {
            "introduced": "1.25.0"
        },
        {
            "fixed": "1.25.13"
        },
        {
            "introduced": "1.26.0"
        },
        {
            "fixed": "1.26.8"
        },
        {
            "introduced": "1.27.0"
        },
        {
            "fixed": "1.27.5"
        },
        {
            "introduced": "1.28.0"
        },
        {
            "fixed": "1.28.1"
        }
    ],
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"
}

Affected versions

kubernetes-1.*
kubernetes-1.10.0-alpha.0
kubernetes-1.10.0-alpha.1
kubernetes-1.10.0-alpha.2
kubernetes-1.10.0-alpha.3
kubernetes-1.11.0-alpha.0
kubernetes-1.11.0-alpha.1
kubernetes-1.11.0-alpha.2
kubernetes-1.12.0-alpha.0
kubernetes-1.12.0-alpha.1
kubernetes-1.12.0-beta.0
kubernetes-1.13.0-alpha.0
kubernetes-1.9.0-alpha.0
kubernetes-1.9.0-alpha.1
kubernetes-1.9.0-alpha.2
kubernetes-1.9.0-alpha.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-3955.json"

Git / github.com/kubernetes/kubernetes

Affected ranges

Type
GIT
Repo
https://github.com/kubernetes/kubernetes
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.24.17"
        },
        {
            "introduced": "1.25.0"
        },
        {
            "fixed": "1.25.13"
        },
        {
            "introduced": "1.26.0"
        },
        {
            "fixed": "1.26.8"
        },
        {
            "introduced": "1.27.0"
        },
        {
            "fixed": "1.27.5"
        },
        {
            "introduced": "1.28.0"
        },
        {
            "fixed": "1.28.1"
        }
    ],
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*"
}

Affected versions

v0.*
v0.13.1-dev
v0.17.0
v1.*
v1.1.0-alpha.0
v1.1.0-alpha.1
v1.10.0-alpha.0
v1.10.0-alpha.1
v1.10.0-alpha.2
v1.10.0-alpha.3
v1.11.0-alpha.0
v1.11.0-alpha.1
v1.11.0-alpha.2
v1.12.0-alpha.0
v1.12.0-alpha.1
v1.13.0-alpha.0
v1.13.0-alpha.1
v1.13.0-alpha.2
v1.13.0-alpha.3
v1.14.0-alpha.0
v1.14.0-alpha.1
v1.14.0-alpha.2
v1.14.0-alpha.3
v1.15.0-alpha.0
v1.15.0-alpha.1
v1.15.0-alpha.2
v1.15.0-alpha.3
v1.16.0-alpha.0
v1.16.0-alpha.1
v1.16.0-alpha.2
v1.16.0-alpha.3
v1.17.0-alpha.0
v1.17.0-alpha.1
v1.17.0-alpha.2
v1.17.0-alpha.3
v1.18.0-alpha.0
v1.18.0-alpha.1
v1.18.0-alpha.2
v1.18.0-alpha.4
v1.18.0-alpha.5
v1.19.0-alpha.0
v1.19.0-alpha.1
v1.19.0-alpha.2
v1.19.0-alpha.3
v1.19.0-beta.0
v1.19.0-beta.1
v1.19.0-beta.2
v1.2.0-alpha.1
v1.2.0-alpha.2
v1.2.0-alpha.3
v1.2.0-alpha.4
v1.2.0-alpha.5
v1.2.0-alpha.6
v1.2.0-alpha.7
v1.2.0-alpha.8
v1.20.0-alpha.0
v1.20.0-alpha.1
v1.20.0-alpha.2
v1.20.0-alpha.3
v1.20.0-beta.0
v1.20.0-beta.1
v1.20.0-beta.2
v1.21.0-alpha.0
v1.21.0-alpha.1
v1.21.0-alpha.2
v1.21.0-alpha.3
v1.21.0-beta.0
v1.21.0-beta.1
v1.22.0-alpha.0
v1.22.0-alpha.1
v1.22.0-alpha.2
v1.22.0-alpha.3
v1.22.0-beta.0
v1.22.0-beta.1
v1.22.0-beta.2
v1.23.0-alpha.0
v1.23.0-alpha.1
v1.23.0-alpha.2
v1.23.0-alpha.3
v1.23.0-alpha.4
v1.24.0
v1.24.0-alpha.0
v1.24.0-alpha.1
v1.24.0-alpha.2
v1.24.0-alpha.3
v1.24.0-alpha.4
v1.24.0-beta.0
v1.24.0-rc.0
v1.24.0-rc.1
v1.24.1
v1.24.1-rc.0
v1.24.10
v1.24.10-rc.0
v1.24.11
v1.24.11-rc.0
v1.24.12
v1.24.12-rc.0
v1.24.13
v1.24.14
v1.24.15
v1.24.16
v1.24.2
v1.24.2-rc.0
v1.24.3
v1.24.3-rc.0
v1.24.4
v1.24.4-rc.0
v1.24.5
v1.24.5-rc.0
v1.24.6
v1.24.6-rc.0
v1.24.7
v1.24.7-rc.0
v1.24.8
v1.24.8-rc.0
v1.24.9
v1.24.9-rc.0
v1.25.0
v1.25.0-alpha.0
v1.25.1
v1.25.1-rc.0
v1.25.10
v1.25.11
v1.25.12
v1.25.2
v1.25.2-rc.0
v1.25.3
v1.25.3-rc.0
v1.25.4
v1.25.4-rc.0
v1.25.5
v1.25.5-rc.0
v1.25.6
v1.25.6-rc.0
v1.25.7
v1.25.7-rc.0
v1.25.8
v1.25.8-rc.0
v1.25.9
v1.26.0
v1.26.1
v1.26.1-rc.0
v1.26.2
v1.26.2-rc.0
v1.26.3
v1.26.3-rc.0
v1.26.4
v1.26.5
v1.26.6
v1.26.7
v1.27.0
v1.27.1
v1.27.2
v1.27.3
v1.27.4
v1.28.0
v1.3.0-alpha.0
v1.3.0-alpha.1
v1.3.0-alpha.2
v1.3.0-alpha.3
v1.3.0-alpha.4
v1.3.0-alpha.5
v1.4.0-alpha.1
v1.4.0-alpha.2
v1.4.0-alpha.3
v1.5.0-alpha.0
v1.5.0-alpha.1
v1.5.0-alpha.2
v1.6.0-alpha.0
v1.6.0-alpha.1
v1.6.0-alpha.2
v1.6.0-alpha.3
v1.7.0-alpha.0
v1.7.0-alpha.1
v1.7.0-alpha.2
v1.7.0-alpha.3
v1.7.0-alpha.4
v1.8.0-alpha.0
v1.8.0-alpha.1
v1.8.0-alpha.2
v1.8.0-alpha.3
v1.9.0-alpha.0
v1.9.0-alpha.1
v1.9.0-alpha.2
v1.9.0-alpha.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-3955.json"