Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgqq-9qh8-wvqv

Опубликовано: 31 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalation

A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.

Пакеты

Наименование

github.com/openshift/hive

go
Затронутые версииВерсия исправления

<= 1.1.16

Отсутствует

EPSS

Процентиль: 48%
0.00248
Низкий

8.8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.

suse-cvrf
около 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 48%
0.00248
Низкий

8.8 High

CVSS3

Дефекты

CWE-284