Loading HuntDB...

GHSA-xc8m-28vv-4pjc

GitHub Security Advisory

Kubelet vulnerable to bypass of seccomp profile enforcement

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

Affected Packages

Go k8s.io/kubernetes
Affected versions: 0 (fixed in 1.24.14)
Go k8s.io/kubernetes
Affected versions: 1.25.0 (fixed in 1.25.10)
Go k8s.io/kubernetes
Affected versions: 1.26.0 (fixed in 1.26.5)
Go k8s.io/kubernetes
Affected versions: 1.27.0 (fixed in 1.27.2)

Related CVEs

Key Information

GHSA ID
GHSA-xc8m-28vv-4pjc
Published
June 16, 2023 9:30 AM
Last Modified
December 12, 2024 7:11 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
k8s.io/kubernetes
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.