Execution with unnecessary privileges in Submariner - CVE-2024-5042
Published: July 19, 2024
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to unnecessary role-based access control permissions. A local user can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
Affected software
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2024-5042
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0