CVE-2023-32192: Kubernetes Apiserver

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to execute arbitrary JavaScript code in the victim browser

Affected products

  • Kubernetes Apiserver: before 0.0.0-20240207153957-4fd7d821d952 (fixed in 0.0.0-20240207153957-4fd7d821d952)
  • Suse Apiserver: before 0.0.0-20240207153957-4fd7d821d952 (fixed in 0.0.0-20240207153957-4fd7d821d952)

Published 2024-10-16. Last modified 2026-06-17.