CVE-2024-53351: Critical severity pipecd vulnerability
Published Mar 21, 2025
·Updated
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
Affected Software
3 affected components
pipecd pipecd
go/github.com/pipe-cd/pipecd<=0.49.0
linuxfoundation Pipecd<=0.49.3
Event History
Mar 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-53351?
CVE-2024-53351 is categorized as a high-severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2024-53351?
To fix CVE-2024-53351, ensure that proper permissions are enforced on service account tokens in pipecd v0.49.
3
What systems are affected by CVE-2024-53351?
CVE-2024-53351 affects versions of pipecd prior to a security patch addressing insecure permissions.
4
What type of vulnerability is CVE-2024-53351?
CVE-2024-53351 is classified as an insecure permissions vulnerability.
5
What attack vector does CVE-2024-53351 expose?
CVE-2024-53351 allows attackers to gain unauthorized access to service account tokens, enabling privilege escalation.