Lack of data validation In k8s.io/kubernetes
Description
Kubernetes privilege escalation vulnerability A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 1.24.17, 1.25.13, 1.26.8, 1.27.5, 1.28.1 | ||
go | 1.24.17, 1.25.13, 1.26.8, 1.27.5, 1.28.1 | ||
go | 1.28.1, 1.27.5, 1.26.8, 1.25.13, 1.24.17 | ||
debian 11 | 1.20.5+really1.20.2-1 | ||
debian 12 | 1.20.5+really1.20.2-1 | ||
debian 13 | 1.20.5+really1.20.2-1 | ||
debian 14 | 1.20.5+really1.20.2-1 | ||
go | 1.24.17, 1.25.13, 1.26.8, 1.27.5, 1.28.1 | ||
go | v1.24.17, v1.25.13, v1.26.8, v1.27.5, v1.28.1 | ||
go | 1.24.17, 1.25.13, 1.26.8, 1.27.5, 1.28.1 |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.