Vulnerabilities (CVE)

Filtered by vendor Microsoft
Filtered by product Azure Setup Kubectl
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23939 1 Microsoft 1 Azure Setup Kubectl 2024-11-21 N/A 3.9 LOW
Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action because it is world writable. This Kubectl tool installer runs `fs.chmodSync(kubectlPath, 777)` to set permissions on the Kubectl binary, however, this allows any local user to replace the Kubectl binary. This allows privilege escalation to t ...

Show More