
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical security vulnerability (CVE-2024-33398) has been identified in piraeus-operator versions 2.5.0 and earlier. The vulnerability stems from a ClusterRole configuration that has been granted list secrets permission, which enables potential attackers to impersonate the service account bound to this ClusterRole and access confidential information across the cluster (GitHub Gist, NVD).
The vulnerability is classified as an Incorrect Access Control issue, with a CVSS v3.1 base score of 7.5 (HIGH) and vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability specifically relates to excessive privileges granted to a ClusterRole in the piraeus-operator, which violates the principle of least privilege by allowing the listing of all secrets within the Kubernetes cluster (NVD, FortiGuard).
The impact of this vulnerability is severe as it allows attackers to access and list confidential information across the entire Kubernetes cluster. Once an attacker obtains the service account token, they can authenticate with the API Server and gain access to all secrets in the cluster. This access to sensitive information could potentially lead to privilege escalation and complete cluster compromise (GitHub Gist).
The vulnerability can be exploited through a multi-step process: First, an attacker needs to obtain the service account token, which could be achieved by compromising a worker node. Then, using the token to authenticate with the API Server, the attacker can access all secrets in the cluster. This access can be leveraged to further elevate privileges and potentially take over the entire cluster (GitHub Gist, GitHub POC).
Users are advised to avoid using versions 2.5.0 and earlier of the piraeus-operator. The vulnerability has been identified and reported, and users should upgrade to a newer version once available that implements proper access controls and follows the principle of least privilege (FortiGuard).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."