Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/openshift/must-gather-operator: CVE-2024-25131 #3349

Closed
GoVulnBot opened this issue Dec 19, 2024 · 2 comments

Comments

@GoVulnBot
Copy link

Advisory CVE-2024-25131 references a vulnerability in the following Go modules:

Module
github.com/openshift/must-gather-operator

Description:
A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard developer user to escalate their privileges to a cluster administrator and pivot to the AWS environment.

References:

No existing reports found with this module or alias.
See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/openshift/must-gather-operator
      vulnerable_at: 0.1.1
summary: CVE-2024-25131 in github.com/openshift/must-gather-operator
cves:
    - CVE-2024-25131
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-25131
    - fix: https://github.com/openshift/must-gather-operator/pull/135
    - fix: https://github.com/openshift/must-gather-operator/pull/138
    - web: https://access.redhat.com/security/cve/CVE-2024-25131
    - web: https://bugzilla.redhat.com/show_bug.cgi?id=2258856
source:
    id: CVE-2024-25131
    created: 2024-12-19T16:01:23.651368517Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/638116 mentions this issue: data/reports: add 6 unreviewed reports

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/637956 mentions this issue: data/reports: add 6 unreviewed reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants