GHSA-2rhx-qhxp-5jpw
MODERATECVE-2024-5042A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
- Affected
- >= 0.16.0-m0, < 0.16.4, >=0, <0.16.4, >=0.17.0
- Fixed in
- 0.16.4
- Weakness
- CWE-250
- Published
- 2024-05-17
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference