-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/kubernetes/kubernetes | go | >= 1.25.0, < 1.25.3 | 1.25.4 |
| github.com/kubernetes/kubernetes | go | >= 1.24.0, < 1.24.8 | 1.24.8 |
| github.com/kubernetes/kubernetes | go | >= 1.23.0, < 1.23.14 | 1.23.14 |
| github.com/kubernetes/kubernetes | go | >= 1.22.0, < 1.22.16 | 1.22.16 |
The vulnerability stems from improper path validation when handling custom resource requests in the same API group. Key functions in the API server's request handling chain:
KEV Misses 88% of Exploited CVEs- Get the report