← לוח פגיעויות

CVE-2024-5042

בינונית 6.6

תיאור (מקור, אנגלית)

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

מדדים

CVSS 3.1
6.6 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-25/7/2026
CWE
CWE-250

קישורים