CVE-2024-5042

Executive Summary

CVE-2024-5042 exposes the Submariner project to privilege escalation via overly permissive RBAC. A privileged attacker can launch malicious containers on cluster nodes, harvest service account tokens, and propagate compromise across the cluster, potentially affecting all nodes.


Authoritative CVE Metadata - CVSS Base Score: 6.6 (MEDIUM) - Published: 2024-05-17T14:15:21.123 - Last Modified: 2026-08-22T23:16:20.927

Original Description: A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

"In all chaos there is a cosmos, in all disorder a secret order."

— Carl Jung
Source: NVD