First published: Fri Mar 21 2025(Updated: )
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PipeCD | ||
go/github.com/pipe-cd/pipecd | <=0.49.0 | |
Pipecd | <=0.49.3 | |
<=0.49.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53351 is categorized as a high-severity vulnerability due to the potential for privilege escalation.
To fix CVE-2024-53351, ensure that proper permissions are enforced on service account tokens in pipecd v0.49.
CVE-2024-53351 affects versions of pipecd prior to a security patch addressing insecure permissions.
CVE-2024-53351 is classified as an insecure permissions vulnerability.
CVE-2024-53351 allows attackers to gain unauthorized access to service account tokens, enabling privilege escalation.