6.1
CVE-2024-5321
- EPSS 0.07%
- Veröffentlicht 18.07.2024 19:15:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle jordan@liggitt.net
- CVE-Watchlists
- Unerledigt
Incorrect permissions on Windows containers logs
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerKubernetes
≫
Produkt
Kubernetes
Default Statusaffected
Version <=
1.27.15
Version
1.27.0
Status
affected
Version <=
1.28.11
Version
1.28.0
Status
affected
Version <=
1.29.6
Version
1.29.0
Status
affected
Version <=
1.30.2
Version
1.30.0
Status
affected
Version
1.27.16
Status
unaffected
Version
1.28.12
Status
unaffected
Version
1.29.7
Status
unaffected
Version
1.30.3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.214 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| jordan@liggitt.net | 6.1 | 1.8 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.