CVE-2024-42480
Last modified
CVE-2024-42480 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clastix | Kamaji | < edge-24.8.2 |
References
- https://github.com/clastix/kamaji/security/advisories/GHSA-6r4j-4rjc-8vw5Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-42480?
How severe is CVE-2024-42480?
How do I fix CVE-2024-42480?
Are you affected by CVE-2024-42480?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
