CVE-2024-3177 - CVE House
Back to Database
Status published Low CVE-2024-3177

Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

Vulnerability Description

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3177

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • tha3e1vl

Affected Vendor

Affected Software

Kubernetes
Vulnerable Versions:
0, v1.28.0 - v1.28.8, v1.29.0 - v1.29.3

Timeline

Official Publish: April 22nd, 2024
Last Modified: September 10th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)