Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2588 | Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. The "edit" ClusterRole is one of Kubernetes default-created ClusterRole, and it has the create/patch/udpate verbs of daemonset resources, create verb of serviceaccount/token resources, and impersonate verb of serviceaccounts resources. A malicious user can leverage access the worker node which has this component to make a cluster-level privilege escalation. |
Github GHSA |
GHSA-h27c-6xm3-mcqp | Withdrawn Advisory: Kanister vulnerable to cluster-level privilege escalation |
Wed, 21 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kanisterio
Kanisterio kanister |
|
| CPEs | cpe:2.3:a:kanisterio:kanister:0:*:*:*:*:*:*:* | |
| Vendors & Products |
Kanisterio
Kanisterio kanister |
|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. The "edit" ClusterRole is one of Kubernetes default-created ClusterRole, and it has the create/patch/udpate verbs of daemonset resources, create verb of serviceaccount/token resources, and impersonate verb of serviceaccounts resources. A malicious user can leverage access the worker node which has this component to make a cluster-level privilege escalation. | |
| Title | Kanister has a potential risk which can be leveraged to make a cluster-level privilege escalation | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-21T16:35:41.804Z
Reserved: 2024-08-12T18:02:04.966Z
Link: CVE-2024-43403
Updated: 2024-08-21T16:35:37.312Z
Status : Deferred
Published: 2024-08-20T22:15:04.703
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-43403
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA