Lucene search

K
cveMitreCVE-2024-33396
HistoryMay 02, 2024 - 7:15 p.m.

CVE-2024-33396

2024-05-0219:15:06
CWE-284
mitre
web.nvd.nist.gov
29
karmada-io
v1.9.0
local code execution
vulnerability

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0

Percentile

9.0%

An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0

Percentile

9.0%