Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-13484

Опубликовано: 28 янв. 2025
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

Отчет

To exploit this flaw, a local attacker must be logged into the system with admin privileges, limiting the possibility of this issue to be exploited. For this reason, this flaw has been rated with a Moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-668
https://bugzilla.redhat.com/show_bug.cgi?id=2269376openshift-gitops-operator-container: Namespace Isolation Break

EPSS

Процентиль: 18%
0.00058
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
около 1 года назад

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

CVSS3: 8.2
github
около 1 года назад

OpenShift GitOps Operator Namespace Isolation Break

suse-cvrf
12 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 18%
0.00058
Низкий

8.2 High

CVSS3