Skip to main content

Improper Restriction of Security Token Assignment

CVE-2024-36533

Severity High
Score 9.8/10

Summary

Insecure permissions in github.com/volcano-sh/volcano versions prior to 1.9.0 allow attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-1259 - Improper Restriction of Security Token Assignment

The System-On-A-Chip (SoC) implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens are improperly protected.

Advisory Timeline

  • Published