Vulnerability CVE-2024-32359


Published: 2024-05-02

Description:
An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.

 References:
http://carina.com
https://github.com/HouqiyuA/k8s-rbac-poc
https://github.com/carina-io/carina
https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906

Copyright 2026, cxsecurity.com

 

Back to Top