A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:4591 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-5042 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2280921 | issue tracking |
https://github.com/advisories/GHSA-2rhx-qhxp-5jpw |