CVE-2023-2727: Kubernetes

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.

Affected products

  • Kubernetes Kubernetes: up to and including 1.24.14; from 1.25.0, up to and including 1.25.10; from 1.26.0, up to and including 1.26.5; from 1.27.0, up to and including 1.27.2

Published 2023-07-03. Last modified 2026-06-17.