Execution with unnecessary privileges in Submariner - CVE-2024-5042

 

Execution with unnecessary privileges in Submariner - CVE-2024-5042

Published: July 19, 2024


Vulnerability identifier: #VU94614
CSH Severity: Medium
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2024-5042
CWE-ID: CWE-250
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to unnecessary role-based access control permissions. A local user can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.


Affected software

Submariner
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2024-5042

Install updates from vendor's website.

Submariner - addressed in versions 0.14.8, 0.15.4, 0.16.4, 0.17.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0

External References

Related Security Bulletins