CVE-2023-32191 - RKE Cluster State Escalation Vulnerability

1 day ago 2
ARTICLE AD BOX
CVE ID : CVE-2023-32191
Published : Oct. 16, 2024, 1:15 p.m. | 24 minutes ago
Description : When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article