NVD Vulnerability Detail
Search Exploit, PoC
CVE-2023-32191
Summary

When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.

Publication Date Oct. 16, 2024, 10:15 p.m.
Registration Date Oct. 17, 2024, 5 a.m.
Last Update Oct. 17, 2024, 1:38 a.m.
Related information, measures and tools
Common Vulnerabilities List