Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-28917

Опубликовано: 09 апр. 2024
Источник: msrc
CVSS3: 6.2
EPSS Низкий

Описание

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, Confidentiality is high (C:H) but integrity is none (I:N) and availability is none (A:N). What does that mean for this vulnerability?

An attacker who successfully exploited this vulnerability could gain access to sensitive information such as Azure IoT Operations secrets and potentially other credentials or access tokens stored within the Kubernetes cluster.

What actions do customers need to take to protect themselves from this vulnerability?

In addition to updating any affected Extensions which are used in their environment, to be protected customers must also update their Azure Arc Agent to version >= 1.14.6 using the steps described here: https://learn.microsoft.com/en-us/cli/azure/connectedk8s?view=azure-cli-latest#az-connectedk8s-upgrade.

According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?

An attacker must have access to the network connected to the targeted Arc-enabled Kubernetes Cluster but does not require permissions to connect or manage the Kubernetes cluster to exploit the vulnerability.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

The vulnerability enables an attacker to compromise a Cluster Extension's identity token and access other components or Azure resources associated with the Arc-enabled Kubernetes cluster.

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker who successfully exploited this vulnerability could leverage the Azure Arc Cluster Extension's identity token by bypassing the Kubernetes namespace's RBAC and access other Azure resources on behalf of the Extension.

Обновления

ПродуктСтатьяОбновление
Azure Arc Cluster microsoft.videoindexer Extension
Azure Arc Cluster microsoft.networkfabricserviceextension Extension
Azure Arc Cluster microsoft.iotoperations.mq Extension
Azure Arc Cluster microsoft.azurekeyvaultsecretsprovider Extension
Azure Arc Cluster microsoft.azure.hybridnetwork Extension
Azure Arc Cluster microsoft.azstackhci.operator Extension
Azure Arc Cluster microsoft.openservicemesh Extension

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

DOS

N/A

EPSS

Процентиль: 34%
0.00138
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
почти 2 года назад

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

CVSS3: 6.2
github
почти 2 года назад

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

CVSS3: 6.2
fstec
почти 2 года назад

Уязвимость расширений кластера Kubernetes с поддержкой Azure Arc, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 34%
0.00138
Низкий

6.2 Medium

CVSS3