6.1
CVE-2024-5321
- EPSS 0.05%
- Published 18.07.2024 19:15:12
- Last modified 21.11.2024 09:47:25
- Source jordan@liggitt.net
- Teams watchlist Login
- Open Login
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorKubernetes
≫
Product
Kubernetes
Default Statusaffected
Version <=
1.27.15
Version
1.27.0
Status
affected
Version <=
1.28.11
Version
1.28.0
Status
affected
Version <=
1.29.6
Version
1.29.0
Status
affected
Version <=
1.30.2
Version
1.30.0
Status
affected
Version
1.27.16
Status
unaffected
Version
1.28.12
Status
unaffected
Version
1.29.7
Status
unaffected
Version
1.30.3
Status
unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.161 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
jordan@liggitt.net | 6.1 | 1.8 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.