CVE-2024-5321
Incorrect permissions on Windows containers logs
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
Se descubrió un problema de seguridad en clústeres de Kubernetes con nodos de Windows donde BUILTIN\Users pueden leer registros de contenedores y NT AUTHORITY\Authenticated Users pueden modificar registros de contenedores.
A flaw was found in Kubernetes clusters with Windows nodes. BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
The components for Red Hat OpenShift for Windows Containers 8.1.3 are now available. This product release includes bug fixes and security updates for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-24 CVE Reserved
- 2024-07-18 CVE Published
- 2024-09-13 CVE Updated
- 2025-04-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/kubernetes/kubernetes/issues/126161 | Issue Tracking | |
https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-5321 | 2024-09-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2298752 | 2024-09-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | >= 1.27.0 <= 1.27.15 Search vendor "Kubernetes" for product "Kubernetes" and version " >= 1.27.0 <= 1.27.15" | en |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | >= 1.28.0 <= 1.28.11 Search vendor "Kubernetes" for product "Kubernetes" and version " >= 1.28.0 <= 1.28.11" | en |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | >= 1.29.0 <= 1.29.6 Search vendor "Kubernetes" for product "Kubernetes" and version " >= 1.29.0 <= 1.29.6" | en |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | >= 1.30.0 <= 1.30.2 Search vendor "Kubernetes" for product "Kubernetes" and version " >= 1.30.0 <= 1.30.2" | en |
Affected
|