Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HKubernetes
APPKubernetes1.5.01.5.11.5.21.5.31.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPEContainer
CWE
Related vulnerabilities
CVE-2026-13019CRITICAL9.8PL ✓same product
Esri Portal for ArcGIS – brak uwierzytelnienia dla krytycznej funkcji API
CVE-2026-33519CRITICAL9.8PL ✓same product
Nieprawidłowa autoryzacja w Esri Portal for ArcGIS — obejście uprawnień
CVE-2025-57870CRITICAL10.0PL ✓same product
SQL Injection w Esri ArcGIS Server — zdalny dostęp bez uwierzytelnienia
CVE-2018-1002105CRITICAL9.8PL ✓same product
Eskalacja uprawnień przez kube-apiserver w Kubernetes — nieautoryzowany dostęp do backendów
CVE-2016-1906CRITICAL9.8PL ✓same product
OpenShift: privilege escalation przez zmianę typu konfiguracji build