Vulnerability Description
Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Kuadrant | <= 0.11.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383Third Party Advisory
- https://github.com/Kuadrant/kuadrant-operatorProduct
- https://www.cncf.io/projects/kuadrant/Product
FAQ
What is CVE-2024-53349?
CVE-2024-53349 is a vulnerability with a CVSS score of 7.4 (HIGH). Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
How severe is CVE-2024-53349?
CVE-2024-53349 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-53349?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Kuadrant.