CVE-2024-36539
CRITICALContour <1.28.3 - Privilege Escalation
Title source: llmDescription
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.1398
EPSS Percentile
94.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-277
Status
published
Products (1)
projectcontour/contour
1.28.3
Published
Jul 24, 2024
Tracked Since
Feb 18, 2026