Skip to content

Commit

Permalink
Merge pull request #5219 from github/skitt-GHSA-2rhx-qhxp-5jpw
Browse files Browse the repository at this point in the history
  • Loading branch information
advisory-database[bot] authored Jan 21, 2025
2 parents fec7351 + a2cb238 commit 97572d4
Showing 1 changed file with 22 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"aliases": [
"CVE-2024-5042"
],
"summary": "Submariner Operator sets unnecessary RBAC permissions in helm charts",
"summary": "Submariner Operator sets unnecessary RBAC permissions",
"details": "A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.",
"severity": [
{
Expand All @@ -25,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
"introduced": "0.16.0"
},
{
"fixed": "0.16.4"
Expand All @@ -47,7 +47,26 @@
"introduced": "0.17.0"
},
{
"last_affected": "0.18.0-m3"
"fixed": "0.17.2"
}
]
}
]
},
{
"package": {
"ecosystem": "Go",
"name": "github.com/submariner-io/submariner-operator"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.15.4"
}
]
}
Expand Down

0 comments on commit 97572d4

Please sign in to comment.