CVE-2023-3893: Kubernetes Csi Proxy

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

Affected products

  • Kubernetes Csi Proxy: up to and including 1.1.2; version 2.0.0 only

Published 2023-11-03. Last modified 2026-06-17.