CVE-2024-25131

HIGH

OpenShift Dedicated - Privilege Escalation

Title source: llm
STIX 2.1

Description

A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard developer user to escalate their privileges to a cluster administrator and pivot to the AWS environment.

References (4)

Core 4

Scores

CVSS v3 8.8
EPSS 0.0075
EPSS Percentile 50.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
openshift/must-gather 0 - 0.0.0-20240604173837-d1557bc283ddGo
Published Dec 19, 2024
Tracked Since Feb 18, 2026