Back to overview

CVE-2024-45496

CRITICAL
9.9
CVSS 3.1
Description
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container.

Metadata

CVE ID
CVE-2024-45496
State
PUBLISHED
Assigner
redhat
Reserved
2024-08-30 10:12 UTC
Published
2024-09-16 23:58 UTC
Last updated
2026-02-25 19:22 UTC
Primary CWE
CWE-269
Improper Privilege Management
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (7)
VendorProductPlatformVersions
4.12.0 ≤ 4.18.0
Red Hat Red Hat OpenShift Container Platform 4.12 v4.12.0-202409131137.p1.g0b1971a.assembly.stream.el8 < *
Red Hat Red Hat OpenShift Container Platform 4.13 v4.13.0-202409130707.p1.gb75d499.assembly.stream.el8 < *
Red Hat Red Hat OpenShift Container Platform 4.14 v4.14.0-202409130708.p1.g9020ea1.assembly.stream.el8 < *
Red Hat Red Hat OpenShift Container Platform 4.15 v4.15.0-202409131835.p1.gbe9d673.assembly.stream.el9 < *
Red Hat Red Hat OpenShift Container Platform 4.16 v4.16.0-202409130937.p1.g5dcfc99.assembly.stream.el9 < *
Red Hat Red Hat OpenShift Container Platform 4.17 v4.17.0-202409182235.p0.g7682a61.assembly.stream.el9 < *
Weakness (CWE)
CWESourceDescription
CWE-269 cna Improper Privilege Management
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Back to overview