CVE-2024-5042: Red Hat Advanced Cluster Management For Kubernetes 2

Medium severity, CVSS 6.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
  • Red Hat Red Hat Openshift Data Foundation 4.20: before 1774540992 (fixed in 1774540992); before 1774540668 (fixed in 1774540668); before 1774541259 (fixed in 1774541259); before 1774541345 (fixed in 1774541345); before 1774541880 (fixed in 1774541880); before 1774541518 (fixed in 1774541518); …
  • Red Hat Rhodf-4.16-Rhel-9: before v4.16.0-19 (fixed in v4.16.0-19)

Published 2024-05-17. Last modified 2026-09-17.