CVE-2024-5042 - CVE House
Back to Database
Status published Medium CVE-2024-5042

Submariner-operator: rbac permissions can allow for the spread of node compromises

Vulnerability Description

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5042

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

RHODF-4.16-RHEL-9, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Management for Kubernetes 2
Vulnerable Versions:
0, 0.15.0, 0.16.0, 0.17.0, 0.18.0-m0, v4.16.0-19, 1774540992, 1774540668, 1774541259, 1774541345, 1774541880, 1774541518, 1774541420, 1774541448, 1774541663, 1774541469, 1774542075, 1774541617, 1774541614, 1774541633, 1774541625, 1774542179, 1774541779, 1774541857, 1774541919, 1774542101

Timeline

Official Publish: May 17th, 2024
Last Modified: June 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N

Weaknesses (CWE)