CVE-2024-53349

high

Description

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster

References

https://www.cncf.io/projects/kuadrant/

https://github.com/Kuadrant/kuadrant-operator

https://gist.github.com/HouqiyuA/2a34c8f95dac7d9d8d7df7732403f383

Details

Source: Mitre, NVD

Published: 2025-03-21

Updated: 2025-04-01

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:C/A:P

Severity: High

CVSS v3

Base Score: 7.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: High