CVE-2024-5321

MEDIUM6.1EPSS 0.07%

Kubernetes sets incorrect permissions on Windows containers logs

Published: 7/18/2024Modified: 2/4/2026
Also known as:GHSA-82m2-cv7p-4m75CGA-58g4-v49f-fmhmGO-2024-2994

Description

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

References (9)