Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-45054
Summary
Hwameistor is a high-availability (HA) local storage system for cloud-native stateful workloads. A security vulnerability was identified in the ClusterRole, which has unrestricted "*" verbs for "*" resources. If a malicious user gains access to a worker node where Hwameistor is deployed, they could exploit these excessive permissions to perform unauthorized actions across the entire cluster, leading to cluster-level privilege escalation. This issue affects github.com/hwameistor/hwameistor versions prior to 0.14.6. All users are advised to upgrade. Users who cannot upgrade should update and restrict the ClusterRole using security-role policies.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- HIGH
- HIGH
- HIGH
CWE-200 - Information Exposure
An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.
References
Advisory Timeline
- Published