Security Advisory

CVE-2024-5042

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-05-17 13:12:00
Last updated 2026-07-19 02:03:22
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.