CVE-2024-36538
https://notcve.org/view.php?id=CVE-2024-36538
Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. • https://gist.github.com/HouqiyuA/f06d1fa07b5287b862c1e0b288f301e5 • CWE-278: Insecure Preserved Inherited Permissions •
CVE-2024-36540
https://notcve.org/view.php?id=CVE-2024-36540
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. • https://gist.github.com/HouqiyuA/a4834f3c8450f9d89e2bc4d5c4beef6a • CWE-284: Improper Access Control •
CVE-2024-36534
https://notcve.org/view.php?id=CVE-2024-36534
Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. • https://gist.github.com/HouqiyuA/0de688e6b874e480ddc1154350368450 • CWE-266: Incorrect Privilege Assignment •
CVE-2024-36533
https://notcve.org/view.php?id=CVE-2024-36533
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. • https://gist.github.com/HouqiyuA/a0e05a26ecc80bd970ac4649faecc930 • CWE-1259: Improper Restriction of Security Token Assignment •
CVE-2024-36537
https://notcve.org/view.php?id=CVE-2024-36537
Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. • https://gist.github.com/HouqiyuA/27879a6366a65fcd5f6c6fcbcf68d8e3 • CWE-284: Improper Access Control •