CVE-2024-39690
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch.
Published:Aug 20, 2024
Last Modified:Aug 14, 2025
EPS:Aug 20, 2024
EPSS Score:0.00157
CVSS Score:8.5
Affected Products
Vendor
Product
Action
Vendor
Clastix
Product
Capsule
Clastix
Capsule
Vendor
Projectcapsule
Product
Capsule
Projectcapsule
Capsule
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
