CVE-2024-5321

Name
CVE-2024-5321
Description
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/kubernetes/kubernetes/issues/126161
mailing-list https://groups.google.com/g/kubernetes-security-announce/c/81c0BHkKNt0

Match rules

CPE URI Source package Min version Max version
kubernetes >= 1.27.0 <= 1.27.15
kubernetes >= 1.28.0 <= 1.28.11
kubernetes >= 1.29.0 <= 1.29.6
kubernetes >= 1.30.0 <= 1.30.2
kubernetes == 1.27.16 == 1.27.16
kubernetes == 1.28.12 == 1.28.12
kubernetes == 1.29.7 == 1.29.7
kubernetes == 1.30.3 == 1.30.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
kubernetes 3.20-community 1.30.0-r3 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable