CVE-2024-5042
CVE-2024-5042: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.6
Medium [CVE-2024-5042] rbac permissions can allow for the spread of node compromises
CVE-2024-5042Source published Source updated
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster. For the submariner operator in Red Hat Advanced Cluster Management for Kubernetes, the submariner-security outlined potential vulnerabilities regarding RBAC permissions being too broad. Those permissions make it possible to create, patch or update statefulsets or replicasets resources. This may allow new privileged containers escaping them and gaining root privileges on any worker nodes where those containers have been deployed within the cluster. Red Hat severity: Moderate — CVSS 6.6…
- Affected products in this advisory
- RHODF-4.16-RHEL-9
- Red Hat Openshift Data Foundation 4.2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- odf4/odf-multicluster-rhel9-operator:v4.16.0-19
- odf4/cephcsi-rhel9:1774540992
- odf4/cephcsi-rhel9-operator:1774540668
- odf4/mcg-core-rhel9:1774541259
21 more entries in the full advisory.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.