CVE-2024-32359

An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () http://carina.com - () http://carina.com -
References () https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906 - () https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906 -
References () https://github.com/HouqiyuA/k8s-rbac-poc - () https://github.com/HouqiyuA/k8s-rbac-poc -
References () https://github.com/carina-io/carina - () https://github.com/carina-io/carina -

03 Jul 2024, 01:56

Type Values Removed Values Added
Summary
  • (es) Un riesgo de autorización RBAC en Carina v0.13.0 y versiones anteriores permite a atacantes locales ejecutar código arbitrario a través de comandos manipulados para obtener los secretos de todo el clúster y apoderarse del clúster.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.9
CWE CWE-285

02 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 16:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-32359

Mitre link : CVE-2024-32359

CVE.ORG link : CVE-2024-32359


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization