SCA: security update for k8s.io/apiextensions-apiserver (GHSA-fp37-c92q-4pwq)

high Tenable Cloud Security Plugin ID 433155

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request
is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are
enforced using roles and role bindings within the namespace, meaning that a user with access only to a
resource in one namespace could create, view update or delete the cluster-scoped resource (according to
their namespace role privileges). Kubernetes affected versions include versions prior to 1.13.9, versions
prior to 1.14.5, versions prior to 1.15.2, and versions 1.7, 1.8, 1.9, 1.10, 1.11, 1.12. (CVE-2019-11247)

See Also

https://github.com/advisories/GHSA-fp37-c92q-4pwq

Plugin Details

Severity: High

ID: 433155

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 8/12/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2019-11247

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/24/2022

Vulnerability Publication Date: 8/5/2019

Reference Information

CVE: CVE-2019-11247

cwe: CWE-863