Skip to content
VulniPulse
Critical9.9Vendor: HighRed Hat Linux

Critical [CVE-2024-45496] Openshift-controller-manager: elevated build pods can lead to node compromise in openshift

This critical-severity Red Hat Linux advisory covers CVE-2024-45496 affecting Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14.

CVE-2024-45496 Published Sep 16, 2024Updated by vendor Sep 16, 2024
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process.

During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted.gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node.

An attacker running code in a privileged container could escalate their permissions on the node running the container. In all versions of OpenShift, the "Custom" build strategy gives developers permission to run arbitrary commands in a privileged container.

This is disabled by default, and documentation explicitly warns that this should only be enabled for highly trusted users (eg: cluster admins). We therefore do not consider this vulnerability a privilege escalation path for "Custom" strategy builds.

Microshift is not affected by this vulnerability. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).

Weakness: CWE-269.

Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; and 3 more.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions
  • openshift4/ose-openshift-controller-manager-rhel8:v4.12.0-202409131137.p1.g0b1971a.assembly.stream.el8
  • openshift4/ose-openshift-controller-manager-rhel8:v4.13.0-202409130707.p1.gb75d499.assembly.stream.el8
  • openshift4/ose-openshift-controller-manager-rhel8:v4.14.0-202409130708.p1.g9020ea1.assembly.stream.el8
  • openshift4/ose-openshift-controller-manager-rhel9:v4.15.0-202409131835.p1.gbe9d673.assembly.stream.el9
  • openshift4/ose-openshift-controller-manager-rhel9:v4.16.0-202409130937.p1.g5dcfc99.assembly.stream.el9
  • openshift4/ose-openshift-controller-manager-rhel9:v4.17.0-202409182235.p0.g7682a61.assembly.stream.el9
  • openshift4/aws-kms-encryption-provider-rhel9:v4.18.0-202501230001.p0.g088dcaf.assembly.stream.el9
  • openshift4/azure-kms-encryption-provider-rhel9:v4.18.0-202501230001.p0.gd4fb1b6.assembly.stream.el9
  • openshift4/azure-service-rhel9-operator:v4.18.0-202501230001.p0.g11ced00.assembly.stream.el9
  • openshift4/cloud-network-config-controller-rhel9:v4.18.0-202501230001.p0.gf648c78.assembly.stream.el9
  • openshift4/container-networking-plugins-microshift-rhel9:v4.18.0-202501230001.p0.g24a6532.assembly.stream.el9
  • openshift4/driver-toolkit-rhel9:v4.18.0-202502100301.p0.g2e139ed.assembly.stream.el9
  • openshift4/egress-router-cni-rhel9:v4.18.0-202501230001.p0.g3193a75.assembly.stream.el9
  • openshift4/frr-rhel9:v4.18.0-202502041302.p0.g1ad8f2e.assembly.stream.el9
  • openshift4/insights-runtime-exporter-rhel9:v4.18.0-202501230001.p0.g7149f2d.assembly.stream.el9
  • openshift4/insights-runtime-extractor-rhel9:v4.18.0-202501230001.p0.g7149f2d.assembly.stream.el9
  • openshift4/kube-metrics-server-rhel9:v4.18.0-202501230001.p0.g962ccca.assembly.stream.el9
  • openshift4/kubevirt-csi-driver-rhel9:v4.18.0-202501230001.p0.gba2234b.assembly.stream.el9
  • openshift4/network-tools-rhel9:v4.18.0-202502111035.p0.gf76635f.assembly.stream.el9
  • openshift4/oc-mirror-plugin-rhel9:v4.18.0-202502100934.p0.gc00c7c9.assembly.stream.el9
  • openshift4/openshift-route-controller-manager-rhel9:v4.18.0-202501230001.p0.g07daee4.assembly.stream.el9
  • openshift4/ose-agent-installer-api-server-rhel9:v4.18.0-202502040032.p0.ge5a4005.assembly.stream.el9
  • openshift4/ose-agent-installer-csr-approver-rhel9:v4.18.0-202502040032.p0.g5348c85.assembly.stream.el9
  • openshift4/ose-agent-installer-node-agent-rhel9:v4.18.0-202502041302.p0.g51a74ac.assembly.stream.el9
  • openshift4/ose-agent-installer-orchestrator-rhel9:v4.18.0-202501230001.p0.g5348c85.assembly.stream.el9
  • openshift4/ose-agent-installer-utils-rhel9:v4.18.0-202501230001.p0.g3f6d1d8.assembly.stream.el9
  • openshift4/ose-apiserver-network-proxy-rhel9:v4.18.0-202501230001.p0.g0e11616.assembly.stream.el9
  • openshift4/ose-aws-cloud-controller-manager-rhel9:v4.18.0-202501230001.p0.gc395190.assembly.stream.el9
  • openshift4/ose-aws-cluster-api-controllers-rhel9:v4.18.0-202501230001.p0.g6bd77fc.assembly.stream.el9
  • openshift4/ose-aws-ebs-csi-driver-rhel9:v4.18.0-202501230001.p0.gb51cd6b.assembly.stream.el9
  • openshift4/ose-aws-ebs-csi-driver-rhel9-operator:v4.18.0-202501230001.p0.g9432fd3.assembly.stream.el9
  • openshift4/ose-aws-pod-identity-webhook-rhel9:v4.18.0-202501230001.p0.g5c43fe8.assembly.stream.el9
  • openshift4/ose-azure-cloud-controller-manager-rhel9:v4.18.0-202501230001.p0.g9c24d76.assembly.stream.el9
  • openshift4/ose-azure-cloud-node-manager-rhel9:v4.18.0-202501230001.p0.g9c24d76.assembly.stream.el9
  • openshift4/ose-azure-cluster-api-controllers-rhel9:v4.18.0-202501230001.p0.g987615c.assembly.stream.el9
  • openshift4/ose-azure-disk-csi-driver-rhel9:v4.18.0-202501241902.p0.g6cced66.assembly.stream.el9
  • openshift4/ose-azure-disk-csi-driver-rhel9-operator:v4.18.0-202501230001.p0.g9432fd3.assembly.stream.el9
  • openshift4/ose-azure-file-csi-driver-operator-rhel9:v4.18.0-202501230001.p0.g9432fd3.assembly.stream.el9
  • openshift4/ose-azure-file-csi-driver-rhel9:v4.18.0-202501230001.p0.g4b34592.assembly.stream.el9
  • openshift4/ose-azure-workload-identity-webhook-rhel9:v4.18.0-202501230001.p0.g344c5dc.assembly.stream.el9
  • RHSA-2024:6705
  • RHSA-2024:6691
  • RHSA-2024:6689
  • RHSA-2024:6685
  • RHSA-2024:6687
  • RHSA-2024:3718
  • RHSA-2024:6122

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" and “Source” build strategies on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.