Description
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6fg2-hvj9-832f | piraeus-operator allows attacker to impersonate service account |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:27:53.612Z
Reserved: 2024-04-23T00:00:00.000Z
Link: CVE-2024-33398
Updated: 2024-08-02T02:27:53.612Z
Status : Deferred
Published: 2024-05-03T16:15:11.393
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-33398
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA