First published: Fri Mar 21 2025(Updated: )
Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kuadrant | ||
Kuadrant | <=0.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-53349 is considered high due to the potential for privilege escalation.
To fix CVE-2024-53349, ensure proper permissions are set on service accounts to prevent unauthorized access.
CVE-2024-53349 allows attackers to access the service account's token, leading to potential privilege escalation in the Kubernetes cluster.
CVE-2024-53349 affects Kuadrant version 0.11.3.
The secrets component in the Kubernetes cluster is exploited in CVE-2024-53349.