CVE-2024-3177
LOWKubernetes - Privilege Escalation
Title source: llmDescription
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.
Exploits (1)
Scores
CVSS v3
2.7
EPSS
0.0640
EPSS Percentile
91.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-20
Status
published
Products (4)
k8s.io/kubernetes
0 - 1.27.13Go
Kubernetes/Kubernetes
< 1.27.12
Kubernetes/Kubernetes
v1.28.0 - v1.28.8
Kubernetes/Kubernetes
v1.29.0 - v1.29.3
Published
Apr 22, 2024
Tracked Since
Feb 18, 2026