CVE-2024-3177Improper Input Validation in Kubernetes

Severity
2.7LOWNVD
EPSS
6.4%
top 8.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 22
Latest updateJun 4

Description

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kube

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages3 packages

Gok8s.io/kubernetes1.29.01.29.4+2
Debiankubernetes/kubernetes< 1.20.5+really1.20.2-1+3
CVEListV5kubernetes/kubernetes1.27.12+2

🔴Vulnerability Details

5
OSV
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes2024-06-04
GHSA
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin2024-04-23
OSV
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin2024-04-23
CVEList
Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin2024-04-22
OSV
CVE-2024-3177: A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the Se2024-04-22

📋Vendor Advisories

3
Red Hat
kubernetes: kube-apiserver: bypassing mountable secrets policy imposed by the ServiceAccount admission plugin2024-04-16
Microsoft
Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin2024-04-09
Debian
CVE-2024-3177: kubernetes - A security issue was discovered in Kubernetes where users may be able to launch ...2024
CVE-2024-3177 — Improper Input Validation in Kubernetes | cvebase