CVE-2024-45041

HIGH
Published Sep 9, 2024 Modified Sep 18, 2024 CWE-269 CWE-732

Description

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It also has path/update verb of validatingwebhookconfigurations resources. This can be used to abuse the SA token of the deployment to retrieve or get ALL secrets in the whole cluster, capture and log all data from requests attempting to update Secrets, or make a webhook deny all Pod create and update requests. This vulnerability is fixed in 0.10.2.

Is your site exposed to CVE-2024-45041?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.3
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Weakness Type (CWE)

CWE-269 CWE-269
CWE-732 CWE-732

Affected Products

Vendor Product
external-secrets external_secrets_operator

References

Frequently Asked Questions

What is CVE-2024-45041? +
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It also has path/update verb of validatingwebhookconfigurations resources. This can be used to abuse the SA token of the deployment to retrieve or get ALL secrets in the whole cluster, capture and log all data from requests attempting to update Secrets, or make a webhook deny all Pod create and update requests. This vulnerability is fixed in 0.10.2. It has a CVSS v3.1 base score of 8.3 (HIGH).
How severe is CVE-2024-45041? +
CVE-2024-45041 has a CVSS v3.1 score of 8.3 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-45041? +
CVE-2024-45041 affects products from external-secrets, specifically: external_secrets_operator. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-45041? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-45041 — free, no signup required.