CVE-2024-53350
CVSS 3.1 Score 7.4 of 10 (high)
Details
Summary
CVE-2024-53350 is a vulnerability affecting kubeslice version 1.3.1. This issue involves insecure permissions, allowing attackers to obtain the service account's token. Obtaining the token grants the attacker elevated privileges, putting the affected Kubernetes environment at risk. Attackers can exploit this vulnerability to perform unauthorized actions, such as deploying malicious containers or modifying sensitive data. Organizations using this version of kubeslice are advised to upgrade to a patched version or take other mitigation measures to prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- KubeSlice