CVE-2024-25132
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-25132 is a vulnerability affecting OpenShift Dedicated's Hive hibernation controller component. A ClusterDeployment resource can be created with incorrect specifications, enabling the installed flag despite the installation not being complete and setting a positive value for the hibernateAfter field. If a ClusterSync resource is also created with the v1alpha1 version, the hibernation controller enters a reconciliation loop, leading to a panic when accessing a non-existent field in the ClusterDeployment's status section, causing a denial-of-service issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.