Количество 2
Количество 2
CVE-2024-33398
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
GHSA-6fg2-hvj9-832f
piraeus-operator allows attacker to impersonate service account
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-33398 There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-6fg2-hvj9-832f piraeus-operator allows attacker to impersonate service account | CVSS3: 7.5 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу