{"id":"GHSA-6fg2-hvj9-832f","summary":"piraeus-operator allows attacker to impersonate service account","details":"There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.","aliases":["CVE-2024-33398","GO-2024-2811"],"modified":"2024-07-03T22:06:25Z","published":"2024-05-03T18:30:36Z","database_specific":{"nvd_published_at":"2024-05-03T16:15:11Z","cwe_ids":["CWE-269"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-03T20:31:38Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33398"},{"type":"WEB","url":"https://gist.github.com/HouqiyuA/d0c11fae5ba4789946ae33175d0f9edb"},{"type":"WEB","url":"https://github.com/HouqiyuA/k8s-rbac-poc"},{"type":"PACKAGE","url":"https://github.com/piraeusdatastore/piraeus-operator"},{"type":"WEB","url":"https://piraeus.io"}],"affected":[{"package":{"name":"github.com/piraeusdatastore/piraeus-operator/v2","ecosystem":"Go","purl":"pkg:golang/github.com/piraeusdatastore/piraeus-operator/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-6fg2-hvj9-832f/GHSA-6fg2-hvj9-832f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}