CVE Feed

    Dashboard / CVE / CVE-2024-45497

    CVE-2024-45497

    A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which allows the attacker to overwrite it. By modifying the config.json file, the attacker can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. This flaw impacts the availability of services dependent on image pulls and exposes sensitive information to unauthorized parties.

    Published:Dec 15, 2024
    Last Modified:Aug 11, 2026
    EPS:Dec 31, 2024
    EPSS Score:0.00559
    CVSS Score:7.6

    Affected Products

    Vendor
    Redhat
    Product
    Jboss Fuse
    Vendor
    Redhat
    Product
    Openshift

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High