Kubelet Vulnerabilities on Windows Nodes: CVE-2023-3676 ARMO named in Gartner® Cool Vendors™ report. A recurring theme among these vulnerabilities is a lapse in input sanitization in the Windows specific porting of the Kubelets.
•4m read time• From armosec.io
Table of contents
Kubelet privilege escalation via Pod spec command injection – CVE-2023-3676Kubelet privilege escalation – CVE-2023-3955Kubernetes CSI proxy privilege escalation – CVE-2023-3893Root causeAm I affected?RecommendationsConclusionKubernetes security platform { powered by Kubescape }. Free forever.Sort: