CVE-2023-32192: Kubernetes Apiserver
High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to execute arbitrary JavaScript code in the victim browser
Affected products
- Kubernetes Apiserver: before 0.0.0-20240207153957-4fd7d821d952 (fixed in 0.0.0-20240207153957-4fd7d821d952)
- Suse Apiserver: before 0.0.0-20240207153957-4fd7d821d952 (fixed in 0.0.0-20240207153957-4fd7d821d952)
Published 2024-10-16. Last modified 2026-06-17.