A security issue was reported in kOps <https://github.com/kubernetes/kops> with the GCP Provider running in Gossip Mode <https://kops.sigs.k8s.io/gossip/>, where Node service account credentials could be used by a container running in the cluster to retrieve sensitive information from the state storage bucket and escalate to cluster-admin permissions.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-1943