CVE-2024-36539

Name
CVE-2024-36539
Description
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://gist.github.com/HouqiyuA/c92f9ec979653dceeea947afd0b47a80

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:projectcontour:contour:*:*:*:*:*:*:*:* contour >= 0 <= 1.28.3
cpe:2.3:a:projectcontour:contour:1.28.3:*:*:*:*:kubernetes:*:* contour == None == 1.28.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
contour edge-community 0.6.1.7494-r1 Matthias Ahouansou <matthias@ahouansou.cz> possibly vulnerable
contour 3.22-community 0.6.1.7494-r1 Matthias Ahouansou <matthias@ahouansou.cz> possibly vulnerable