4
CVSSv2

CVE-2016-1905

Published: 03/02/2016 Updated: 12/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.7 | Impact Score: 4 | Exploitability Score: 3.1
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes -

Vendor Advisories

An authorization flaw was discovered in Kubernetes; the API server did not properly check user permissions when handling certain requests An authenticated remote attacker could use this flaw to gain additional access to resources such as RAM and disk space ...