{
  "threat_severity" : "Important",
  "public_date" : "2023-08-23T13:00:00Z",
  "bugzilla" : {
    "description" : "kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation",
    "id" : "2227126",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2227126"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-269",
  "details" : [ "A security issue was discovered in Kubernetes where a user\nthat can create pods on Windows nodes may be able to escalate to admin \nprivileges on those nodes. Kubernetes clusters are only affected if they\ninclude Windows nodes.", "A vulnerability was found in Kubernetes. This flaw allows a user who can create pods on Windows nodes to escalate to admin privileges on those nodes." ],
  "statement" : "Kubernetes clusters are only affected if they include Windows nodes. Any Kubernetes environment with Windows nodes is impacted. Run kubectl get nodes -l kubernetes.io/os=windows to see if any Windows nodes are in use.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4.10",
    "release_date" : "2023-08-29T00:00:00Z",
    "advisory" : "RHSA-2023:4835",
    "cpe" : "cpe:/a:redhat:openshift:4.10::el8",
    "package" : "openshift4-wincw/windows-machine-config-rhel8-operator:5.1.2-3"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.11",
    "release_date" : "2023-08-28T00:00:00Z",
    "advisory" : "RHSA-2023:4780",
    "cpe" : "cpe:/a:redhat:openshift:4.11::el8",
    "package" : "openshift4-wincw/windows-machine-config-rhel8-operator:6.0.2-5"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.12",
    "release_date" : "2023-08-28T00:00:00Z",
    "advisory" : "RHSA-2023:4777",
    "cpe" : "cpe:/a:redhat:openshift:4.12::el8",
    "package" : "openshift4-wincw/windows-machine-config-rhel8-operator:7.1.1-9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.13",
    "release_date" : "2023-08-30T00:00:00Z",
    "advisory" : "RHSA-2023:4885",
    "cpe" : "cpe:/a:redhat:openshift:4.13::el9",
    "package" : "openshift4-wincw/windows-machine-config-rhel9-operator:8.0.2-9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.14",
    "release_date" : "2023-11-27T00:00:00Z",
    "advisory" : "RHSA-2023:7515",
    "cpe" : "cpe:/a:redhat:openshift:4.14::el9",
    "package" : "openshift4-wincw/windows-machine-config-rhel9-operator:9.0.0-105"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-3676\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-3676" ],
  "name" : "CVE-2023-3676",
  "csaw" : false
}