<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:24:42 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-1260 — Kube-apiserver: privesc</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-1260</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; github.com/openshift/apiserver-library-go, Red Hat OpenShift Container Platform 4.10, Red Hat OpenShift Container Platform 4.11, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4&lt;/p&gt;
&lt;p&gt;An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions &amp;#34;update, patch&amp;#34; the &amp;#34;pods/ephemeralcontainers&amp;#34; subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; github.com/openshift/apiserver-library-go, Red Hat OpenShift Container Platform 4.10, Red Hat OpenShift Container Platform 4.11, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4&lt;/p&gt;
&lt;p&gt;An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions &amp;#34;update, patch&amp;#34; the &amp;#34;pods/ephemeralcontainers&amp;#34; subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-1260</guid>
    </item>
  </channel>
</rss>
