HouqiyuA

2 exploits Active since May 2024
CVE-2024-32359 WRITEUP MEDIUM WORKING POC
Carina <0.13.0 - RCE
An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.
CVSS 6.9
CVE-2024-33398 WRITEUP HIGH WORKING POC
Piraeusdatastore Piraeus-operator - Improper Privilege Management
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
CVSS 7.5