Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform - CVE-2024-45496
Published: September 19, 2024
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions during the build initialization step. A remote user can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node.
Affected software
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2024-45496
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift