PT-2024-20772 · Red Hat+1 · Openshift Dedicated+1

Robb Gatica

+1

·

Published

2024-12-31

·

Updated

2025-01-10

·

CVE-2024-25133

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenShift Dedicated (affected versions not specified)
Description A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-25133
GHSA-WGQQ-9QH8-WVQV
GO-2024-3360
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Openshift Dedicated
Suse