CVE-2024-36533
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
In short
Volcano v1.8.2 has insecure file permissions that allow attackers to steal the service account token, giving them full access to sensitive data and administrative capabilities. This is a critical flaw that can compromise the entire system.
Technical detail
Improper permission configuration in Volcano v1.8.2 exposes service account credentials, enabling unauthorized token retrieval via local or network access. Successful exploitation grants privilege escalation and unrestricted access to protected resources managed by the service account.
Summary generated and translated by AI from the official description.
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a