Database/Control plane, storage & DevOps
Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that let
Impact
Volcano 1.8.2 ships over-permissive settings that let an attacker obtain the scheduler's service account token. Volcano is the component that decides which tenant's job lands on which GPU, so holding its token means reading and rewriting placement for the entire cluster, plus whatever cluster-wide objects that account can touch.
Who can reach it
An attacker who reaches the Volcano components in-cluster. The advisory reports it as network-reachable with no privileges required.
What to do
Upgrade Volcano to 1.10.0-alpha.0 or later and restart the scheduler, controller and webhook deployments. Rotate the Volcano service account token after upgrading and review RBAC bindings for the account, since the pre-upgrade token may already be out.
References
Related entries
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCVE-2024-37080 · VMware vCenter Server (DCERPC heap overflow)Critical
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCVE-2024-3817 · Terraform (go-getter)Critical
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCVE-2024-4323 · Fluent BitCritical
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCVE-2024-47575 · Fortinet FortiManagerCritical
- GitHub Enterprise Server: Forged SAML response with encrypted assertions enabledCVE-2024-4985 · GitHub Enterprise ServerCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.