{"id":"UBUNTU-CVE-2024-5651","details":"A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted FenceAgentsRemediation for a fence agent supporting  --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This RCE leads to a privilege escalation, first as the service account running the operator, then to another service account with cluster-admin privileges.","modified":"2026-02-04T03:10:47.311683Z","published":"2024-08-12T13:38:00Z","withdrawn":"2025-06-23T15:57:34Z","related":["CVE-2024-5651"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-5651"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-5651"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-5651"}],"affected":[{"package":{"name":"fence-agents","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/fence-agents?arch=src?distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.0.19-1","4.0.21-2","4.0.22-2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5651.json"}},{"package":{"name":"fence-agents","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/fence-agents?arch=src?distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.0.25-1","4.0.25-2ubuntu1","4.0.25-2ubuntu1.1","4.0.25-2ubuntu1.2","4.0.25-2ubuntu1.3"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5651.json"}},{"package":{"name":"fence-agents","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/fence-agents?arch=src?distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.4.0-2","4.5.2-1","4.5.2-1ubuntu0.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5651.json"}},{"package":{"name":"fence-agents","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/fence-agents?arch=src?distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.7.1-1ubuntu7","4.7.1-1ubuntu8","4.7.1-1ubuntu8.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5651.json"}},{"package":{"name":"fence-agents","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/fence-agents?arch=src?distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.12.1-2~exp1ubuntu2","4.12.1-2~exp1ubuntu4"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-5651.json"}}],"schema_version":"1.7.3"}