CVE-2024-36532

CRITICAL

kruise <1.6.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Scores

CVSS v3 10.0
EPSS 0.0013
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-281
Status published
Published Jun 21, 2024
Tracked Since Feb 18, 2026