GPU VulnDB

Database/Container, Kubernetes & orchestration

Kubernetes (kube-apiserver): Init/ephemeral container envFrom bypasses the ServiceAccount mountable-secrets policy

CVE-2024-3177Container, Kubernetes & orchestrationcurated

Impact

Init/ephemeral container envFrom bypasses the ServiceAccount mountable-secrets policy

Who can reach it

Cluster user with namespace access

What to do

Rolling control-plane upgrade; no GPU drain

Fleet impact

How widespread

Universal component, low impact - every cluster runs the ServiceAccount admission plugin

Cost to remediate

daemon-restart - control-plane-only upgrade, no GPU node drain needed

Why it hits the whole fleet

envFrom bypasses the mountable-secrets restriction, leaking secrets across a namespace boundary; control-plane-scoped and low severity, so not a fleet emergency

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.