VDB

RHSA-2023%3A6156

RHSA-2023%3A6156 PUBLISHED CVSS 3.4000000953674316 LOW

A flaw was found in Kubernetes. This issue occurs when Kubernetes allows a local authenticated attacker to bypass security restrictions, caused by a flaw when using the localhost type for a seccomp profile but specifying an empty profile field. An attacker can bypass the seccomp profile enforcement by sending a specially crafted request.

Risk Scores

CVSS 3.1
3.4000000953674316
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64, openshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64, openshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64
Red Hatopenshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, openshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64, openshift4-wincw/windows-machine-config-rhel9-operator@sha256:6238c841ed9684453ac6167a666269e16175d724fd3a7c34b230dbf7244932de_amd64
Red Hatopenshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64 as a component of Red Hat OpenShift Container Platform 4.13openshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64, openshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64, openshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64
Red Hatopenshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64 as a component of Red Hat OpenShift Container Platform 4.13*, openshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64, openshift4-wincw/windows-machine-config-operator-bundle@sha256:ee24ac6ea9ba7c1067327d66b421815f88acff31165e07256de322bd02df4910_amd64

Timeline

  • Oct 30, 2023 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • May 21, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›