CVE-2024-53349

I

nsecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster

Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:kuadrant:*:*:*:*:*:*:*:*

History

01 Apr 2025, 20:21

Type Values Removed Values Added
First Time Linuxfoundation kuadrant
Linuxfoundation
CPE cpe:2.3:a:linuxfoundation:kuadrant:*:*:*:*:*:*:*:*
References () https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383 - () https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383 - Third Party Advisory
References () https://github.com/Kuadrant/kuadrant-operator - () https://github.com/Kuadrant/kuadrant-operator - Product
References () https://www.cncf.io/projects/kuadrant/ - () https://www.cncf.io/projects/kuadrant/ - Product

24 Mar 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
Summary
  • (es) Los permisos inseguros en kuadrant v0.11.3 permiten a los atacantes obtener acceso al token de la cuenta de servicio, lo que lleva a una escalada de privilegios a través del componente secretes en el clúster k8s
CWE CWE-269

21 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-21 16:15

Updated : 2025-04-01 20:21


NVD link : CVE-2024-53349

Mitre link : CVE-2024-53349

CVE.ORG link : CVE-2024-53349


JSON object : View

Products Affected
CWE
CWE-269

Improper Privilege Management