CVE-2024-5042

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

Scoring

Severity
MEDIUM
CVSS base score
6.6
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N
EPSS probability
0.50%
CWE
CWE-250
Published
2024-05-17
Last modified
2026-08-22

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs