CVE-2024-25131
Linux openSUSE vulnerability analysis and mitigation

Overview

A vulnerability was discovered in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated, tracked as CVE-2024-25131. The vulnerability was disclosed on December 19, 2024, and allows a non-privileged user on the cluster to create a MustGather object with specially crafted contents and set the most privileged service account to run the job (NVD).

Technical details

The vulnerability stems from improper input validation (CWE-20) in the MustGather CRD implementation. The flaw exists because no permissions are defined to access the MustGather CRD, allowing developer-privileged accounts to create such resources through a bypass in Managed Resources Admission Webhook. The vulnerability has a CVSS v3.1 base score of 8.8 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (Red Hat CVE).

Impact

The vulnerability allows a standard developer user to escalate their privileges to a cluster administrator. Once cluster administrator privileges are obtained, the attacker can read the kube-system/osdManage secret and pivot to the AWS environment with administrator privileges (Bugzilla).

Mitigation and workarounds

The vulnerability has been addressed through multiple fixes: removing the ability to pass in custom mustgather images (GitHub PR 135) and preventing values from the MustGather resource from bleeding into other fields from the Job template (GitHub PR 138). The recommended fixes include allowing only cluster-admin role users to create MustGather objects, replacing the Job definition template with Go structs, and validating user inputs (Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux openSUSE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-62291HIGH8.1
  • strongSwanstrongSwan
  • strongswan
NoYesJan 16, 2026
CVE-2026-0891HIGH8.1
  • Mozilla FirefoxMozilla Firefox
  • firefox
NoYesJan 13, 2026
CVE-2025-24528HIGH7.1
  • KerberosKerberos
  • krb5-pkinit-openssl
NoYesJan 16, 2026
CVE-2026-0890MEDIUM5.4
  • Mozilla FirefoxMozilla Firefox
  • cpe:2.3:a:mozilla:firefox_esr
NoYesJan 13, 2026
CVE-2025-43904MEDIUM4.2
  • Linux DebianLinux Debian
  • libnss_slurm2_24_11
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management