CVE-2024-5651
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted FenceAgentsRemediation for a fence agent supporting --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This RCE leads to a privilege escalation, first as the service account running the operator, then to another service account with cluster-admin privileges.
Published:Aug 12, 2024
Last Modified:Apr 15, 2026
EPS:Aug 12, 2024
EPSS Score:0.28556
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Redhat
Product
Workload Availability Far
Redhat
Workload Availability Far
Vendor
Redhat
Product
Workload Availability Fence Agents Remediation
Redhat
Workload Availability Fence Agents Remediation
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
