PT-2025-1002 · Karmada+1 · Karmada+1

Shiro-Bako

+1

·

Published

2025-01-03

·

Updated

2025-01-10

·

CVE-2024-56513

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Karmada versions prior to 1.12.0
Description: The issue is related to excessive privileges in PULL mode clusters, allowing an attacker who can authenticate as the karmada-agent to obtain administrative privileges over the entire federation system, including all registered member clusters. This can be exploited by abusing the permissions of the karmadactl register command. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For Karmada versions prior to 1.12.0, update to version 1.12.0 or later to restrict the access permissions of pull mode member clusters to control plane resources. As a temporary workaround, restrict the access permissions of pull mode member clusters to control plane resources according to Karmada Component Permissions Docs.

Exploit

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-00077
CVE-2024-56513
GHSA-MG7W-C9X2-XH7R
GO-2025-3364
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Karmada
Suse