Arbitrary code execution vulnerability when using shared Kubernetes cluster
CVE-2023-44392

8.3HIGH

Key Information:

Vendor

Garden-io

Status
Vendor
CVE Published:
9 October 2023

What is CVE-2023-44392?

Garden, an automation tool for Kubernetes development and testing, has a vulnerability due to an insecure deserialization in the cryo library. This issue allows attackers with access to the Kubernetes cluster to store malicious serialized objects in the ConfigMap. When users execute the garden test or garden run commands, these objects are fetched and deserialized, potentially leading to remote code execution on the user's machine. Patches have been implemented in versions 0.13.17 and 0.12.65, addressing this security concern. Users are urged to upgrade to these versions to maintain a secure Kubernetes environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

garden < 0.12.65 < 0.12.65

garden >= 0.13.0, < 0.13.17 < 0.13.0, 0.13.17

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.