meta-virtualization/recipes-containers
Soumya Sambu 67b0ef4256 kubernetes: Fix CVE-2023-2727, CVE-2023-2728
Users may be able to launch containers using images that are restricted by
ImagePolicyWebhook when using ephemeral containers, Kubernetes clusters are
only affected if the ImagePolicyWebhook admission plugin is used together
with ephemeral containers.

Users may be able to launch containers that bypass the mountable secrets
policy enforced by the ServiceAccount admission plugin when using ephemeral
containers. The policy ensures pods running with a service account may only
reference secrets specified in the service account's secrets field. Kuberenetes
clusters are only affected if the ServiceAccount admission plugin and the
`kubernetes.io/enforce-mountab'le-secrets` annotation are used teogether with
ephemeralcontainers.

CVE: CVE-2023-2727, CVE-2023-2728

Affected Versions
1.27.0 - v1.27.2
v1.26.0 - v1.26.5
v1.25.0 - v1.25.10
<= v1.24.14

master branch(kubernetes v1.28.2) is not impacted
mickledore branch(kubernetes v1.27.5) is not impacted

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-2727
https://nvd.nist.gov/vuln/detail/CVE-2023-2728

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
2023-11-21 04:07:47 +00:00
..
buildah buildah: add recipe for buildah v1.26 2022-09-19 10:31:08 -04:00
catatonit catatonit: Integrate version 0.1.7 2022-09-19 10:30:56 -04:00
cgroup-lite global: update licence values to SPDX values 2022-02-18 13:07:10 -05:00
conmon conmon: update to v2.1.0 2022-03-21 17:31:28 -04:00
container-host-config container-host-config: extend to native and nativesdk 2023-03-02 16:25:47 -05:00
containerd containerd: upgrade to 1.6.19 2023-04-12 13:02:37 -04:00
cri-o container-host-config: provide /etc/containers/policy.json 2023-03-02 16:25:47 -05:00
cri-tools cri-tools: update to v1.23.0 2022-03-21 17:31:28 -04:00
criu criu: fix patch fuzz and remove unused patch 2022-08-03 23:06:59 -04:00
crun crun: update to 1.4.3 2022-03-21 17:31:28 -04:00
docker docker-ce: bump SRCREV_docker 2023-08-16 13:34:55 +00:00
docker-compose global: overrides syntax conversion 2021-08-02 17:17:53 -04:00
docker-distribution docker-distribution: fix for CVE-2023-2253 2023-07-25 14:53:37 -04:00
go-digest global: convert github SRC_URIs to use https protocol 2021-11-03 09:37:00 -04:00
go-errors global: convert github SRC_URIs to use https protocol 2021-11-03 09:37:00 -04:00
go-spf13-cobra global: convert github SRC_URIs to use https protocol 2021-11-03 09:37:00 -04:00
go-spf13-pflag global: convert github SRC_URIs to use https protocol 2021-11-03 09:37:00 -04:00
k3s k3s: update recipe formatting and map googlesource to github 2022-06-20 12:08:58 -04:00
kubernetes kubernetes: Fix CVE-2023-2727, CVE-2023-2728 2023-11-21 04:07:47 +00:00
lxc lxc: add -L and -f for curl in templates-use-curl-instead-of-wget.patch 2023-03-17 15:32:16 -04:00
lxcfs global: update licence values to SPDX values 2022-02-18 13:07:10 -05:00
nerdctl nerdctl: fix installed-vs-shipped with usrmerge 2023-09-13 13:41:01 +00:00
oci-image-spec oci-image-spec: update to 1.0.2 2022-03-21 17:31:29 -04:00
oci-image-tools oci-image-tools: adjust GOROOT, CGO_CFLAGS and CGO_LDFALGS 2022-06-20 12:09:51 -04:00
oci-runtime-spec oci-runtime-spec: update to 1.0.2-tip 2022-03-21 17:31:29 -04:00
oci-runtime-tools oci-runtime-tools: adjust GOROOT, CGO_CFLAGS and CGO_LDFALGS 2022-06-20 12:09:51 -04:00
oci-systemd-hook global: update licence values to SPDX values 2022-02-18 13:07:10 -05:00
podman podman: Fix merge typo 2022-08-31 08:19:34 -04:00
podman-compose podman-compose: switch 1.0.3 to stable branch 2022-06-01 12:42:09 -04:00
podman-tui containers: introduce podman-tui 2022-03-30 09:42:46 -04:00
riddler riddler: adjust GOROOT, CGO_CFLAGS and CGO_LDFALGS 2022-06-20 12:09:51 -04:00
runc runc-docker: update to 1.1.4-tip 2022-12-22 10:28:08 -05:00
singularity singularity: Drop explicit runtime dep glibc 2022-08-20 23:19:28 -04:00
skopeo container-host-config: provide /etc/containers/policy.json 2023-03-02 16:25:47 -05:00
sloci-image global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
tini global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
umoci umoci: adjust CGO_CFLAGS and CGO_LDFLAGS settings 2022-06-20 12:09:51 -04:00