{
  "threat_severity" : "Important",
  "public_date" : "2023-11-14T16:00:00Z",
  "bugzilla" : {
    "description" : "kubernetes: Insufficient input sanitization in in-tree storage plugin leads to privilege escalation on Windows nodes",
    "id" : "2247163",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2247163"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-20",
  "details" : [ "A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.", "A flaw was found in Kubernetes, where a user who can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes." ],
  "statement" : "Any Kubernetes environment with Windows nodes is impacted. Run kubectl get nodes -l kubernetes.io/os=windows to see if any Windows nodes are in use. \nKubernetes audit logs can be used to detect if this vulnerability is being exploited. Persistent Volume create events with local path fields containing special characters, which are a strong indication of exploitation.",
  "acknowledgement" : "Red Hat would like to thank Tomer Peled for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4.11",
    "release_date" : "2023-12-06T00:00:00Z",
    "advisory" : "RHSA-2023:7662",
    "cpe" : "cpe:/a:redhat:openshift:4.11::el8",
    "package" : "openshift4-wincw/windows-machine-config-operator-bundle:v6.0.3-8"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.11",
    "release_date" : "2023-12-06T00:00:00Z",
    "advisory" : "RHSA-2023:7662",
    "cpe" : "cpe:/a:redhat:openshift:4.11::el8",
    "package" : "openshift4-wincw/windows-machine-config-rhel8-operator:6.0.3-9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.12",
    "release_date" : "2023-12-11T00:00:00Z",
    "advisory" : "RHSA-2023:7710",
    "cpe" : "cpe:/a:redhat:openshift:4.12::el8",
    "package" : "openshift4-wincw/windows-machine-config-operator-bundle:v7.2.0-29"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.12",
    "release_date" : "2023-12-11T00:00:00Z",
    "advisory" : "RHSA-2023:7710",
    "cpe" : "cpe:/a:redhat:openshift:4.12::el8",
    "package" : "openshift4-wincw/windows-machine-config-rhel8-operator:7.2.0-30"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.13",
    "release_date" : "2023-12-11T00:00:00Z",
    "advisory" : "RHSA-2023:7709",
    "cpe" : "cpe:/a:redhat:openshift:4.13::el9",
    "package" : "openshift4-wincw/windows-machine-config-operator-bundle:v8.1.1-7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.13",
    "release_date" : "2023-12-11T00:00:00Z",
    "advisory" : "RHSA-2023:7709",
    "cpe" : "cpe:/a:redhat:openshift:4.13::el9",
    "package" : "openshift4-wincw/windows-machine-config-rhel9-operator:8.1.1-6"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.14",
    "release_date" : "2024-03-07T00:00:00Z",
    "advisory" : "RHSA-2024:1203",
    "cpe" : "cpe:/a:redhat:openshift:4.14::el9",
    "package" : "openshift4-wincw/windows-machine-config-operator-bundle:v9.0.1-15"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.14",
    "release_date" : "2024-03-07T00:00:00Z",
    "advisory" : "RHSA-2024:1203",
    "cpe" : "cpe:/a:redhat:openshift:4.14::el9",
    "package" : "openshift4-wincw/windows-machine-config-rhel9-operator:9.0.1-16"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.14",
    "release_date" : "2024-03-07T00:00:00Z",
    "advisory" : "RHSA-2024:1203",
    "cpe" : "cpe:/a:redhat:openshift:4.14::el9",
    "package" : "openshift4/windows-machine-config-operator-bundle:v9.0.1-15"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.15",
    "release_date" : "2024-02-27T00:00:00Z",
    "advisory" : "RHSA-2024:0954",
    "cpe" : "cpe:/a:redhat:openshift:4.15::el9",
    "package" : "openshift4-wincw/windows-machine-config-operator-bundle:v10.15.0-43"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.15",
    "release_date" : "2024-02-27T00:00:00Z",
    "advisory" : "RHSA-2024:0954",
    "cpe" : "cpe:/a:redhat:openshift:4.15::el9",
    "package" : "openshift4-wincw/windows-machine-config-rhel9-operator:10.15.0-46"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-5528\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-5528\nhttps://github.com/kubernetes/kubernetes/issues/121879" ],
  "name" : "CVE-2023-5528",
  "csaw" : false
}