Incorrect default permissions in Kubernetes - CVE-2024-5321

 

Incorrect default permissions in Kubernetes - CVE-2024-5321

Published: September 9, 2024


Vulnerability identifier: #VU96953
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-5321
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information or alter container logs

The vulnerability exists due to incorrect default permissions in Kubernetes clusters with Windows nodes. A local user with access to the system can view and modify contents of the container logs.


Affected software

Kubernetes
Fedora
kubernetes
IBM Cloud Pak for Watson AIOps
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Observability with Instana
OpenShift Container Platform for Windows Containers

How to mitigate CVE-2024-5321

Install updates from vendor's website.

Kubernetes - addressed in versions 1.27.16, 1.28.12, 1.29.7, 1.30.3
kubernetes - update to 1.29.7-1.fc40
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1
OpenShift Container Platform for Windows Containers - addressed in versions 7.2.2, 8.1.3, 9.0.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
IBM Automation Decision Services - update to 24.0.0.0.2
IBM Observability with Instana - update to 279

External References

Related Security Bulletins