GHSA-82m2-cv7p-4m75
GitHub Security Advisory
Kubernetes sets incorrect permissions on Windows containers logs
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
Affected Packages
Go
k8s.io/kubernetes
Affected versions:
0
(fixed in 1.27.16)
Go
k8s.io/kubernetes
Affected versions:
1.28.0
(fixed in 1.28.12)
Go
k8s.io/kubernetes
Affected versions:
1.29.0
(fixed in 1.29.7)
Go
k8s.io/kubernetes
Affected versions:
1.30.0
(fixed in 1.30.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 16, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.