CVE Database
/

CVE-2024-45497

Back to search

CVE-2024-45497

Published: Dec 31, 2024

Modified: Feb 3, 2026

PUBLISHED

CVSS v3.1

7.6

HIGH

Description

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which allows the attacker to overwrite it. By modifying the config.json file, the attacker can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. This flaw impacts the availability of services dependent on image pulls and exposes sensitive information to unauthorized parties.

VendorProductVersions

Unknown

openshift

affected
4.16

Red Hat

Red Hat OpenShift Container Platform 4.12

unaffected
v4.12.0-202506062300.p0.gb870fc6.assembly.stream.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.13

unaffected
v4.13.0-202507061330.p0.g9abb220.assembly.stream.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
v4.14.0-202506112307.p0.g700dc11.assembly.stream.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
v4.16.0-202506062300.p0.gd26f300.assembly.stream.el9 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
v4.17.0-202507011904.p0.g2b2ba3b.assembly.stream.el9 - < *

Red Hat

Red Hat OpenShift Container Platform 4.18

unaffected
v4.18.0-202506062012.p0.g0a6f6eb.assembly.stream.el9 - < *

Red Hat

Red Hat OpenShift Container Platform 4.2

unaffected
sha256:23043d4a73f0d25d0959030e3d9b8020e4453a748addcb5c5955415953ad30a3 - < *

Red Hat

Red Hat Fuse 7

All versions

Red Hat

Red Hat OpenShift Container Platform 4

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

High

References

RHSA-2025:10270
vendor-advisory
x_refsource_REDHAT
RHSA-2025:10294
vendor-advisory
x_refsource_REDHAT
RHSA-2025:10747
vendor-advisory
x_refsource_REDHAT
RHSA-2025:9269
vendor-advisory
x_refsource_REDHAT
RHSA-2025:9562
vendor-advisory
x_refsource_REDHAT
RHSA-2025:9759
vendor-advisory
x_refsource_REDHAT
RHSA-2025:9765
vendor-advisory
x_refsource_REDHAT
RHBZ#2308673
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now