GPU VulnDB

Database/Control plane, storage & DevOps

Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that let

CVE-2024-36533Control plane, storage & DevOpsGHSA-5g3x-8g2v-r8x8curated

Impact

Volcano 1.8.2 ships over-permissive settings that let an attacker obtain the scheduler's service account token. Volcano is the component that decides which tenant's job lands on which GPU, so holding its token means reading and rewriting placement for the entire cluster, plus whatever cluster-wide objects that account can touch.

Who can reach it

An attacker who reaches the Volcano components in-cluster. The advisory reports it as network-reachable with no privileges required.

What to do

Upgrade Volcano to 1.10.0-alpha.0 or later and restart the scheduler, controller and webhook deployments. Rotate the Volcano service account token after upgrading and review RBAC bindings for the account, since the pre-upgrade token may already be out.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.