CVE-2024-5042

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
Configurations

No configuration.

History

21 Nov 2024, 09:46

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2024:4591 - () https://access.redhat.com/errata/RHSA-2024:4591 -
References () https://access.redhat.com/security/cve/CVE-2024-5042 - () https://access.redhat.com/security/cve/CVE-2024-5042 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2280921 - () https://bugzilla.redhat.com/show_bug.cgi?id=2280921 -
References () https://github.com/advisories/GHSA-2rhx-qhxp-5jpw - () https://github.com/advisories/GHSA-2rhx-qhxp-5jpw -

17 Jul 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4591 -
Summary
  • (es) Se encontró un fallo en el proyecto Submariner. Debido a permisos innecesarios de control de acceso basados en roles, un atacante privilegiado puede ejecutar un contenedor malicioso en un nodo que puede permitirle robar tokens de cuentas de servicio y comprometer aún más otros nodos y potencialmente todo el clúster.

20 May 2024, 06:15

Type Values Removed Values Added
References
  • () https://github.com/advisories/GHSA-2rhx-qhxp-5jpw -

17 May 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 14:15

Updated : 2024-11-21 09:46


NVD link : CVE-2024-5042

Mitre link : CVE-2024-5042

CVE.ORG link : CVE-2024-5042


JSON object : View

Products Affected

No product.

CWE
CWE-250

Execution with Unnecessary Privileges