CVE-2024-53350

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Mar 21, 2025
Updated: Apr 1, 2025
CWE ID 269

Summary

CVE-2024-53350 is a vulnerability affecting kubeslice version 1.3.1. This issue involves insecure permissions, allowing attackers to obtain the service account's token. Obtaining the token grants the attacker elevated privileges, putting the affected Kubernetes environment at risk. Attackers can exploit this vulnerability to perform unauthorized actions, such as deploying malicious containers or modifying sensitive data. Organizations using this version of kubeslice are advised to upgrade to a patched version or take other mitigation measures to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share