{"id":"GHSA-r6cc-7wj7-gfx2","summary":"Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation","details":"Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.","aliases":["CVE-2023-3893","GO-2023-2176"],"modified":"2025-07-09T15:32:55Z","published":"2023-11-03T18:30:24Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-11-03T20:42:49Z","nvd_published_at":"2023-11-03T18:15:08Z","cwe_ids":["CWE-20"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3893"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/119594"},{"type":"WEB","url":"https://github.com/kubernetes-csi/csi-proxy/commit/0e83a68159111e4ee510f5aa56d47ba97bda60c7"},{"type":"WEB","url":"https://github.com/kubernetes-csi/csi-proxy/commit/2523e6674dedf3de27f84235efec28555da24664"},{"type":"PACKAGE","url":"https://github.com/kubernetes-csi/csi-proxy"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/lWksE2BoCyQ"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20231221-0004"}],"affected":[{"package":{"name":"github.com/kubernetes-csi/csi-proxy/v2","ecosystem":"Go","purl":"pkg:golang/github.com/kubernetes-csi/csi-proxy/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-alpha.0"},{"fixed":"2.0.0-alpha.1"}]}],"versions":["2.0.0-alpha.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json"}},{"package":{"name":"github.com/kubernetes-csi/csi-proxy","ecosystem":"Go","purl":"pkg:golang/github.com/kubernetes-csi/csi-proxy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0-rc1"},{"fixed":"1.1.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.1.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json"}},{"package":{"name":"github.com/kubernetes-csi/csi-proxy","ecosystem":"Go","purl":"pkg:golang/github.com/kubernetes-csi/csi-proxy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20230821192013-2523e6674ded"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json"}},{"package":{"name":"github.com/kubernetes-csi/csi-proxy","ecosystem":"Go","purl":"pkg:golang/github.com/kubernetes-csi/csi-proxy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.1.3-0"},{"fixed":"1.1.3-0.20230821192013-2523e6674ded"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}