CVE-2024-53349

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:kuadrant:*:*:*:*:*:*:*:*

History

01 Apr 2025, 20:21

Type Values Removed Values Added
References () https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383 - () https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383 - Third Party Advisory
References () https://github.com/Kuadrant/kuadrant-operator - () https://github.com/Kuadrant/kuadrant-operator - Product
References () https://www.cncf.io/projects/kuadrant/ - () https://www.cncf.io/projects/kuadrant/ - Product
CPE cpe:2.3:a:linuxfoundation:kuadrant:*:*:*:*:*:*:*:*
First Time Linuxfoundation
Linuxfoundation kuadrant

24 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-269
Summary
  • (es) Los permisos inseguros en kuadrant v0.11.3 permiten a los atacantes obtener acceso al token de la cuenta de servicio, lo que lleva a una escalada de privilegios a través del componente secretes en el clúster k8s
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

21 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-21 16:15

Updated : 2025-04-01 20:21


NVD link : CVE-2024-53349

Mitre link : CVE-2024-53349

CVE.ORG link : CVE-2024-53349


JSON object : View

Products Affected

linuxfoundation

  • kuadrant
CWE
CWE-269

Improper Privilege Management