CVE-2024-5651
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-5651 is a newly discovered vulnerability affecting the Fence Agents Remediation operator. This issue enables a Remote Code Execution (RCE) Primitive by allowing the execution of arbitrary commands through the --ssh-path/--telnet-path arguments. A low-privilege user, such as a developer, can exploit this vulnerability by creating a specially crafted FenceAgentsRemediation for a fence agent supporting these arguments. Successful exploitation results in privilege escalation, first to the service account running the operator and then to another service account with cluster-admin privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.