Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 909091 (CVE-2023-1943) - <sys-cluster/kops-1.28.2: account credential leakage into containers
Summary: <sys-cluster/kops-1.28.2: account credential leakage into containers
Status: RESOLVED FIXED
Alias: CVE-2023-1943
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://www.openwall.com/lists/oss-se...
Whiteboard: ~4 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2023-06-24 19:08 UTC by John Helmert III
Modified: 2024-12-10 21:37 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-06-24 19:08:15 UTC
"A security issue was reported in kOps <https://github.com/kubernetes/kops>
with the GCP Provider running in Gossip Mode
<https://kops.sigs.k8s.io/gossip/>, where Node service account credentials
could be used by a container running in the cluster to retrieve sensitive
information from the state storage bucket and escalate to cluster-admin
permissions."

Fixed in 1.25.4, 1.26.2.
Comment 1 Larry the Git Cow gentoo-dev 2024-02-07 13:59:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=677085fa88ff4f533465505cfb5f9d3bcdc57b84

commit 677085fa88ff4f533465505cfb5f9d3bcdc57b84
Author:     Christopher Fore <csfore@posteo.net>
AuthorDate: 2024-01-07 04:44:36 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2024-02-07 13:59:30 +0000

    sys-cluster/kops: add 1.28.2, security bump
    
    Bug: https://bugs.gentoo.org/909091
    Signed-off-by: Christopher Fore <csfore@posteo.net>
    Closes: https://github.com/gentoo/gentoo/pull/34688
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 sys-cluster/kops/Manifest           |  1 +
 sys-cluster/kops/kops-1.28.2.ebuild | 27 +++++++++++++++++++++++++++
 2 files changed, 28 insertions(+)