PT-2024-6989 · Red Hat · Openshift Container Platform

Thibault Guittet

·

Published

2024-08-30

·

Updated

2025-01-09

·

CVE-2024-45496

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenShift Container Platform (affected versions not specified)
Description The issue is related to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08238
CVE-2024-45496
GHSA-J8GH-87RX-C7W9
GO-2024-3128

Affected Products

Openshift Container Platform