CVE-2023-1260: Kubernetes Kube-Apiserver

High severity, CVSS 8.0. EPSS: 1.6% chance of exploitation in the next 30 days.

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow evasion of SCC admission restrictions, thereby gaining control of a privileged pod.

Affected products

  • Kubernetes Kube-Apiserver: affected versions not specified
  • Red Hat Openshift Container Platform: version 4.10 only; version 4.11 only; version 4.12 only; version 4.13 only

Published 2023-09-24. Last modified 2026-06-17.