suse · CVE-2023-2728

Quick triage

Priority: medium Published: 2023-06-16 23:15:45 UTC Updated: 2026-03-05 03:56:37 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-2728 severity moderate: SUSE including 63 source package names (govulncheck-vulndb-0.0.20250807T150727-1.1, govulncheck-vulndb-0.0.20250814T182633-160000.1.2, …), 178 product×package rows across 27 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7, … (27 product lines)): Fixed 162, Will Not Fix 14, Known Not Affected 2.

Description:

Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account's secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.

cvelogic Threat Intelligence