Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 14 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chaos-mesh chaos Mesh
|
|
| CPEs | cpe:2.3:a:chaos-mesh:chaos_mesh:2.6.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Chaos-mesh chaos Mesh
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T03:37:05.270Z
Reserved: 2024-05-30T00:00:00
Link: CVE-2024-36538
Updated: 2024-07-30T15:32:36.676Z
Status : Analyzed
Published: 2024-07-24T19:15:04.487
Modified: 2025-10-14T14:41:57.080
Link: CVE-2024-36538
No data.
OpenCVE Enrichment
No data.
Weaknesses