PT-2024-31406 · Unknown · Hwameistor
Younaman
·
Published
2024-08-28
·
Updated
2024-09-12
·
CVE-2024-45054
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hwameistor versions prior to 0.14.6
Description
Hwameistor is a high-availability local storage system for cloud-native stateful workloads. This ClusterRole has excessive permissions, allowing a malicious user who can access the worker node with Hwameistor's deployment to abuse these permissions and perform any actions on the whole cluster, resulting in a cluster-level privilege escalation.
Recommendations
For versions prior to 0.14.6, upgrade to version 0.14.6 or later.
For users unable to upgrade, update and limit the ClusterRole using security-role as a temporary workaround.
Exploit
Fix
Incorrect Privilege Assignment
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hwameistor