VDB

DEBIAN-CVE-2023-2431

DEBIAN-CVE-2023-2431 PUBLISHED CVSS 5.5 MEDIUM

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:12kubernetes0, 0, 0
Debian:11kubernetes0, 0, 0
Debian:13kubernetes0, 0, 0
Debian:14kubernetes0, 0, 0

Exploit Intelligence

Timeline

  • Jun 16, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›