CVE Feed

    Dashboard / CVE / CVE-2024-45041

    CVE-2024-45041

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It also has path/update verb of validatingwebhookconfigurations resources. This can be used to abuse the SA token of the deployment to retrieve or get ALL secrets in the whole cluster, capture and log all data from requests attempting to update Secrets, or make a webhook deny all Pod create and update requests. This vulnerability is fixed in 0.10.2.

    Published:Sep 9, 2024
    Last Modified:Sep 18, 2024
    EPS:Sep 9, 2024
    EPSS Score:0.00096
    CVSS Score:8.3

    Affected Products

    Vendor
    External-secrets
    Product
    External-secrets
    Vendor
    External-secrets
    Product
    External Secrets Operator

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High