PT-2025-1002 · Karmada+1 · Karmada+1
Shiro-Bako
+1
·
Published
2025-01-03
·
Updated
2025-01-10
·
CVE-2024-56513
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Karmada versions prior to 1.12.0
Description:
The issue is related to excessive privileges in PULL mode clusters, allowing an attacker who can authenticate as the karmada-agent to obtain administrative privileges over the entire federation system, including all registered member clusters. This can be exploited by abusing the permissions of the
karmadactl register command. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.Recommendations:
For Karmada versions prior to 1.12.0, update to version 1.12.0 or later to restrict the access permissions of pull mode member clusters to control plane resources. As a temporary workaround, restrict the access permissions of pull mode member clusters to control plane resources according to Karmada Component Permissions Docs.
Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Karmada
Suse