CVE-2024-5651: Fence-agents-remediation: fence agent command line options leads to remote code execution
A flaw was found in fence agents that rely on SSH/Telnet could be abused to obtain a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user (i.e. a user with developer access) can create a specifically crafted FenceAgentsRemediation for a fence agent supporting --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This RCE leads to a privilege escalation; first as the service account running the operator, then to another service account with cluster-admin privileges.
Other sources
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted FenceAgentsRemediation for a fence agent supporting --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This RCE leads to a privilege escalation, first as the service account running the operator, then to another service account with cluster-admin privileges.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5651?
CVE-2024-5651 has a high severity rating due to its potential for Remote Code Execution.
What can exploit CVE-2024-5651?
CVE-2024-5651 can be exploited by low-privilege users who can supply arbitrary commands in the --ssh-path or --telnet-path arguments.
How do I fix CVE-2024-5651?
To fix CVE-2024-5651, update the affected fence agents to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-5651?
CVE-2024-5651 affects users of Fence Agents that are configured to use SSH or Telnet.
What are the risks associated with CVE-2024-5651?
The risks of CVE-2024-5651 include unauthorized execution of commands which can compromise the integrity and security of the affected systems.