๐Ÿ” CVE Alert

CVE-2024-5042

MEDIUM 6.6

Submariner-operator: rbac permissions can allow for the spread of node compromises

CVSS Score
6.6
EPSS Score
0.1%
EPSS Percentile
19th

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

CWE CWE-250
Published May 17, 2024
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

Red Hat / RHODF-4.16-RHEL-9
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4.2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4591 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6503 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-5042 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2280921 github.com: https://github.com/advisories/GHSA-2rhx-qhxp-5jpw