{"id":"GHSA-8gwj-m6vh-2g6j","summary":"kOps privilege escalation vulnerability","details":"Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.\n","aliases":["CVE-2023-1943","GO-2023-2125"],"modified":"2024-08-21T14:56:58.067583Z","published":"2023-10-12T00:30:29Z","database_specific":{"github_reviewed_at":"2023-10-18T18:29:01Z","nvd_published_at":"2023-10-12T00:15:10Z","cwe_ids":["CWE-250"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1943"},{"type":"WEB","url":"https://github.com/kubernetes/kops/issues/15539"},{"type":"PACKAGE","url":"https://github.com/kubernetes/kops"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/yrCE1x89oaU"}],"affected":[{"package":{"name":"k8s.io/kops","ecosystem":"Go","purl":"pkg:golang/k8s.io/kops"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-8gwj-m6vh-2g6j/GHSA-8gwj-m6vh-2g6j.json"}},{"package":{"name":"k8s.io/kops","ecosystem":"Go","purl":"pkg:golang/k8s.io/kops"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.26.0"},{"fixed":"1.26.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-8gwj-m6vh-2g6j/GHSA-8gwj-m6vh-2g6j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}