CVE-2024-33398
May 3, 2024, 4:15 p.m.
Tags
Product(s) Impacted
piraeus-operator
- 2.5.0
- earlier
Description
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
Weaknesses
Date
Published: May 3, 2024, 4:15 p.m.
Last Modified: May 3, 2024, 4:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org
References
https://gist.github.com/
cve@mitre.org
https://github.com/
cve@mitre.org
https://github.com/
cve@mitre.org
https://piraeus.io/
cve@mitre.org