Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform - CVE-2024-45496

 

Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform - CVE-2024-45496

Published: September 19, 2024


Vulnerability identifier: #VU97615
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45496
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions during the build initialization step. A remote user can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node.


Affected software

Red Hat OpenShift Container Platform
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2024-45496

Install updates from vendor's website.

Red Hat OpenShift Container Platform - addressed in versions 4.14.37, 4.12.66, 4.13.50, 4.15.33, 4.16.13
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00

External References

Related Security Bulletins