Security Patch Fix for CVE-2023-2727 (bsc#1211630) and CVE-2023-2728 (bsc#1211631)
- added patch: kube-apiserver-admission-plugin-policy.patch
- new kube-apiserver component patch prevents ephemeral containers:
** from using an image that is restricted by ImagePolicyWebhook (CVE-2023-2727)
** from bypassing the mountable secrets policy enforced by the ServiceAccount admission plugin (CVE-2023-2728)
OBS-URL: https://build.opensuse.org/request/show/1093309
OBS-URL: https://build.opensuse.org/package/show/devel:kubic/kubernetes1.23?expand=0&rev=21