Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2618 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch. |
Github GHSA |
GHSA-mq69-4j5w-3qwp | Capsule tenant owner with "patch namespace" permission can hijack system namespaces |
Thu, 14 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. | Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch. |
Wed, 21 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectcapsule
Projectcapsule capsule |
|
| CPEs | cpe:2.3:a:projectcapsule:capsule:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Projectcapsule
Projectcapsule capsule |
Tue, 20 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clastix
Clastix capsule |
|
| CPEs | cpe:2.3:a:clastix:capsule:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Clastix
Clastix capsule |
|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. | |
| Title | Capsule tenant owner with "patch namespace" permission can hijack system namespaces | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-14T13:32:03.818Z
Reserved: 2024-06-27T18:44:13.035Z
Link: CVE-2024-39690
Updated: 2024-08-20T15:08:00.655Z
Status : Modified
Published: 2024-08-20T15:15:21.340
Modified: 2025-08-14T14:15:30.037
Link: CVE-2024-39690
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA