Логотип exploitDog
bind: "CVE-2024-3177"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-3177"

Количество 13

Количество 13

ubuntu логотип

CVE-2024-3177

больше 1 года назад

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
EPSS: Низкий
redhat логотип

CVE-2024-3177

больше 1 года назад

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2024-3177

больше 1 года назад

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
EPSS: Низкий
msrc логотип

CVE-2024-3177

больше 1 года назад

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-3177

больше 1 года назад

A security issue was discovered in Kubernetes where users may be able ...

CVSS3: 2.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1404-1

больше 1 года назад

Security update for kubernetes1.23

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1403-1

больше 1 года назад

Security update for kubernetes1.24

EPSS: Низкий
redos логотип

ROS-20240522-03

больше 1 года назад

Уязвимость kubernetes

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-pxhw-596r-rwq5

больше 1 года назад

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVSS3: 2.7
EPSS: Низкий
fstec логотип

BDU:2024-04110

больше 1 года назад

Уязвимость компонента KUBE-APISERVER программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю запускать контейнеры в обход политики безопасности

CVSS3: 2.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02423-2

4 месяца назад

Security update for kubernetes1.23

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3343-1

около 1 года назад

Security update for kubernetes1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3341-1

около 1 года назад

Security update for kubernetes1.23

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
7%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
7%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
7%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 2.7
7%
Низкий
больше 1 года назад
debian логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able ...

CVSS3: 2.7
7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1404-1

Security update for kubernetes1.23

7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1403-1

Security update for kubernetes1.24

7%
Низкий
больше 1 года назад
redos логотип
ROS-20240522-03

Уязвимость kubernetes

CVSS3: 2.7
7%
Низкий
больше 1 года назад
github логотип
GHSA-pxhw-596r-rwq5

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVSS3: 2.7
7%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-04110

Уязвимость компонента KUBE-APISERVER программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю запускать контейнеры в обход политики безопасности

CVSS3: 2.7
7%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02423-2

Security update for kubernetes1.23

4 месяца назад
suse-cvrf логотип
SUSE-SU-2024:3343-1

Security update for kubernetes1.24

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3341-1

Security update for kubernetes1.23

около 1 года назад

Уязвимостей на страницу