Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383 | Third Party Advisory |
https://github.com/Kuadrant/kuadrant-operator | Product |
https://www.cncf.io/projects/kuadrant/ | Product |
Configurations
History
01 Apr 2025, 20:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:linuxfoundation:kuadrant:*:*:*:*:*:*:*:* | |
First Time |
Linuxfoundation
Linuxfoundation kuadrant |
|
References | () https://www.cncf.io/projects/kuadrant/ - Product | |
References | () https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383 - Third Party Advisory | |
References | () https://github.com/Kuadrant/kuadrant-operator - Product |
21 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-21 16:15
Updated : 2025-04-01 20:21
NVD link : CVE-2024-53349
Mitre link : CVE-2024-53349
JSON object : View
Products Affected
linuxfoundation
- kuadrant
CWE
No CWE.