CVE-2024-43403 : KANISTERIO KANISTER UP TO 0.110.0 CREATE/PATCH/UDPATE PRIVILEGES MANAGEMENT

Description

Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. The “edit” ClusterRole is one of Kubernetes default-created ClusterRole, and it has the create/patch/udpate verbs of daemonset resources, create verb of serviceaccount/token resources, and impersonate verb of serviceaccounts resources. A malicious user can leverage access the worker node which has this component to make a cluster-level privilege escalation.

References

https://github.com/kanisterio/kanister/security/advisories/GHSA-h27c-6xm3-mcqp

https://github.com/kanisterio/kanister/blob/master/helm/kanister-operator/templates/rbac.yaml#L49

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-10698 : TENDA AC6 15.03.05.19 /GOFORM/SETONLINEDEVNAME FORMSETDEVICENAME DEVNAME STACK-BASED OVERFLOW

CVE-2024-10698 : TENDA AC6 15.03.05.19 /GOFORM/SETONLINEDEVNAME FORMSETDEVICENAME DEVNAME STACK-BASED OVERFLOW

Description A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function

CVE-2024-41745 : IBM CICS TX STANDARD 11.1 WEB UI CROSS SITE SCRIPTING

CVE-2024-41745 : IBM CICS TX STANDARD 11.1 WEB UI CROSS SITE SCRIPTING

Description IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript

CVE-2024-49770 : OAK UP TO 17.1.2 API CONTEXT.SEND PATH TRAVERSAL

CVE-2024-49770 : OAK UP TO 17.1.2 API CONTEXT.SEND PATH TRAVERSAL

Description `oak` is a middleware framework for Deno’s native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and