Description

Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE List1.8.2affected

github.com/volcano-sh/volcano

Browse Go / github.com/volcano-sh/volcano
GitHub AdvisoryBefore 1.10.0-alpha.0 · Fixed in 1.10.0-alpha.0affected
GitHub AdvisoryBefore 1.10.0-alpha.0 · Fixed in 1.10.0-alpha.0affected

References

7