MEDIUM 6.1 Go

Kubernetes sets incorrect permissions on Windows containers logs

GHSA-82m2-cv7p-4m75 · CVE-2024-5321 · GO-2024-2994

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.

Ready to move

Start Securing

Free, no credit card | First findings in minutes