CVE-2024-5321

MEDIUM

Kubernetes Windows Node Container Logs Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.

Scores

CVSS v3 6.1
EPSS 0.0031
EPSS Percentile 22.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (9)
k8s.io/kubernetes 0 - 1.27.16Go
Kubernetes/Kubernetes 1.27.0 - 1.27.15
Kubernetes/Kubernetes 1.27.16
Kubernetes/Kubernetes 1.28.0 - 1.28.11
Kubernetes/Kubernetes 1.28.12
Kubernetes/Kubernetes 1.29.0 - 1.29.6
Kubernetes/Kubernetes 1.29.7
Kubernetes/Kubernetes 1.30.0 - 1.30.2
Kubernetes/Kubernetes 1.30.3
Published Jul 18, 2024
Tracked Since Feb 18, 2026