Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can access the worker node which has hwameistor's deployment, he/she can abuse these excessive permissions to do whatever he/she likes to the whole cluster, resulting in a cluster-level privilege escalation. This issue has been patched in version 0.14.6. All users are advised to upgrade. Users unable to upgrade should update and limit the ClusterRole using security-role.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hwameistor
Hwameistor hwameistor |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:hwameistor:hwameistor:*:*:*:*:*:go:*:* | |
Vendors & Products |
Hwameistor
Hwameistor hwameistor |
Wed, 28 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 28 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can access the worker node which has hwameistor's deployment, he/she can abuse these excessive permissions to do whatever he/she likes to the whole cluster, resulting in a cluster-level privilege escalation. This issue has been patched in version 0.14.6. All users are advised to upgrade. Users unable to upgrade should update and limit the ClusterRole using security-role. | |
Title | Potential Permission Leakage of Cluster Level in hwameistor | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-28T19:50:22.959Z
Updated: 2024-08-28T20:09:27.302Z
Reserved: 2024-08-21T17:53:51.332Z
Link: CVE-2024-45054
Vulnrichment
Updated: 2024-08-28T20:09:19.092Z
NVD
Status : Analyzed
Published: 2024-08-28T20:15:08.547
Modified: 2024-09-12T17:50:11.233
Link: CVE-2024-45054
Redhat
No data.