Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-3177: Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin #194

Open
pacoxu opened this issue Nov 12, 2024 · 1 comment
Labels
priority/medium Medium(4.0≤Score<7.0) CVSS Score CVE
Milestone

Comments

@pacoxu
Copy link
Member

pacoxu commented Nov 12, 2024

Affected Versions
kube-apiserver v1.29.0 - v1.29.3
kube-apiserver v1.28.0 - v1.28.8
kube-apiserver <= v1.27.12

kubernetes/kubernetes#124322

@pacoxu pacoxu added the priority/medium Medium(4.0≤Score<7.0) CVSS Score CVE label Nov 12, 2024
Copy link

Hi @pacoxu,
Thanks for opening an issue!
We will look into it as soon as possible.

Details Instructions for interacting with me using comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the [gh-ci-bot](https://github.com/wzshiming/gh-ci-bot) repository.

@pacoxu pacoxu added this to the v1.26 milestone Nov 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
priority/medium Medium(4.0≤Score<7.0) CVSS Score CVE
Projects
None yet
Development

No branches or pull requests

1 participant