CVE-2024-5042
Executive Summary
CVE-2024-5042 exposes Submariner’s unnecessary RBAC permissions, allowing a privileged attacker to launch malicious containers on a node. This can lead to theft of service‑account tokens, lateral movement across nodes, and potential full cluster compromise. The flaw highlights the critical need for strict RBAC enforcement and container isolation in Kubernetes environments.
Authoritative CVE Metadata - CVSS Base Score: 6.6 (MEDIUM) - Published: 2024-05-17T14:15:21.123 - Last Modified: 2026-08-21T17:16:28.443
Original Description: A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
"We may encounter many defeats but we must not be defeated."
— Maya Angelou