#VU94614 Execution with unnecessary privileges in Submariner - CVE-2024-5042
Published: July 19, 2024
Submariner
Submariner
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to unnecessary role-based access control permissions. A local user can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.