{"id":"GO-2023-1891","summary":"Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes","details":"Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes","aliases":["CVE-2023-2727","GHSA-qc2g-gmh6-95p4"],"modified":"2026-03-17T04:46:03.498617Z","published":"2024-08-20T20:31:35Z","related":["CGA-rwjh-jgjp-43j3"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2023-1891","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qc2g-gmh6-95p4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/07/06/2"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/118640"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118356"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118471"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118473"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118474"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118512"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8"}],"affected":[{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.24.15"},{"introduced":"1.25.0"},{"fixed":"1.25.11"},{"introduced":"1.26.0"},{"fixed":"1.26.6"},{"introduced":"1.27.0"},{"fixed":"1.27.3"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1891.json"}}],"schema_version":"1.7.5"}