THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-45497 (HIGH 7.6) — A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from priva

[NVD] CVE-2024-45497 (HIGH 7.6) — A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from priva

lownvdPublished 2024-12-31

CVE-2024-45497 CVSS: 7.6 HIGH Published: 2024-12-31T03:15:05.543

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which all

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-45497