CVE-2024-45054

Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can access the worker node which has hwameistor's deployment, he/she can abuse these excessive permissions to do whatever he/she likes to the whole cluster, resulting in a cluster-level privilege escalation. This issue has been patched in version 0.14.6. All users are advised to upgrade. Users unable to upgrade should update and limit the ClusterRole using security-role.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hwameistor:hwameistor:*:*:*:*:*:go:*:*

History

12 Sep 2024, 17:50

Type Values Removed Values Added
First Time Hwameistor hwameistor
Hwameistor
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 2.8
v2 : unknown
v3 : 6.7
CPE cpe:2.3:a:hwameistor:hwameistor:*:*:*:*:*:go:*:*
References () https://github.com/hwameistor/hwameistor/blob/main/helm/hwameistor/templates/clusterrole.yaml - () https://github.com/hwameistor/hwameistor/blob/main/helm/hwameistor/templates/clusterrole.yaml - Product
References () https://github.com/hwameistor/hwameistor/commit/edf4cebed73cadd230bf97eab65c5311f2858450 - () https://github.com/hwameistor/hwameistor/commit/edf4cebed73cadd230bf97eab65c5311f2858450 - Patch
References () https://github.com/hwameistor/hwameistor/issues/1457 - () https://github.com/hwameistor/hwameistor/issues/1457 - Issue Tracking
References () https://github.com/hwameistor/hwameistor/issues/1460 - () https://github.com/hwameistor/hwameistor/issues/1460 - Issue Tracking
References () https://github.com/hwameistor/hwameistor/security/advisories/GHSA-mgwr-h7mv-fh29 - () https://github.com/hwameistor/hwameistor/security/advisories/GHSA-mgwr-h7mv-fh29 - Vendor Advisory

29 Aug 2024, 13:25

Type Values Removed Values Added
Summary
  • (es) Hwameistor es un sistema de almacenamiento local de alta disponibilidad para cargas de trabajo nativas de la nube con estado. Este ClusterRole tiene * verbos de * recursos. Si un usuario malintencionado puede acceder al nodo de trabajo que tiene la implementación de hwameistor, puede abusar de estos permisos excesivos para hacer lo que quiera con todo el clúster, lo que da como resultado una escalada de privilegios a nivel de clúster. Este problema se ha corregido en la versión 0.14.6. Se recomienda a todos los usuarios que actualicen. Los usuarios que no puedan actualizar deben actualizar y limitar el ClusterRole mediante security-role.

28 Aug 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-28 20:15

Updated : 2024-09-12 17:50


NVD link : CVE-2024-45054

Mitre link : CVE-2024-45054

CVE.ORG link : CVE-2024-45054


JSON object : View

Products Affected

hwameistor

  • hwameistor
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor