gist.github.com
https://gist.github.com/HouqiyuA/a0e05a26ecc80bd970ac4649faecc930 CVE-2024-36533
Volcano has insecure permissions
Description
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
volcanoBrowse volcano / volcanoDefault status: unknown | CVE List | 1.8.2 | affected |
github.com/volcano-sh/volcanoBrowse Go / github.com/volcano-sh/volcano | GitHub Advisory | Before 1.10.0-alpha.0 · Fixed in 1.10.0-alpha.0 | affected |
volcano.sh/volcanoBrowse Go / volcano.sh/volcano | GitHub Advisory | Before 1.10.0-alpha.0 · Fixed in 1.10.0-alpha.0 | affected |
References
7github.com
https://github.com/volcano-sh/volcano github.com
https://github.com/volcano-sh/volcano/commit/55963f71c76cb85cea1cdb9582ea7d58cfbedcf8 github.com
https://github.com/volcano-sh/volcano/issues/3446 github.com
https://github.com/volcano-sh/volcano/pull/3449 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36533 pkg.go.dev
https://pkg.go.dev/vuln/GO-2024-3034