Arbitrary code execution vulnerability when using shared Kubernetes cluster
CVE-2023-44392
8.3HIGH
What is CVE-2023-44392?
Garden, an automation tool for Kubernetes development and testing, has a vulnerability due to an insecure deserialization in the cryo library. This issue allows attackers with access to the Kubernetes cluster to store malicious serialized objects in the ConfigMap. When users execute the garden test or garden run commands, these objects are fetched and deserialized, potentially leading to remote code execution on the user's machine. Patches have been implemented in versions 0.13.17 and 0.12.65, addressing this security concern. Users are urged to upgrade to these versions to maintain a secure Kubernetes environment.
Affected Version(s)
garden < 0.12.65 < 0.12.65
garden >= 0.13.0, < 0.13.17 < 0.13.0, 0.13.17
