THREAT OPS › Threat News › [NVD] CVE-2024-45497 (HIGH 7.6) — A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from priva
[NVD] CVE-2024-45497 (HIGH 7.6) — A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from priva
CVE-2024-45497 CVSS: 7.6 HIGH Published: 2024-12-31T03:15:05.543
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which all
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2024-45497cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-45497