Количество 4
Количество 4
CVE-2024-5042
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
CVE-2024-5042
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
GHSA-2rhx-qhxp-5jpw
Submariner Operator sets unnecessary RBAC permissions
BDU:2024-05068
Уязвимость программного обеспечения взаимодействия модулей и служб в кластерах Kubernetes Submariner Operator, связанная с ошибками при управлении привилегиями, позволяющая нарушителю запустить на узле произвольный контейнер
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-5042 A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster. | CVSS3: 6.6 | 0% Низкий | больше 1 года назад | |
CVE-2024-5042 A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster. | CVSS3: 6.6 | 0% Низкий | больше 1 года назад | |
GHSA-2rhx-qhxp-5jpw Submariner Operator sets unnecessary RBAC permissions | CVSS3: 6.6 | 0% Низкий | больше 1 года назад | |
BDU:2024-05068 Уязвимость программного обеспечения взаимодействия модулей и служб в кластерах Kubernetes Submariner Operator, связанная с ошибками при управлении привилегиями, позволяющая нарушителю запустить на узле произвольный контейнер | CVSS3: 6.6 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу