<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:17:35.664109+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04110</id>
    <title>bdu:2024-04110</title>
    <updated>2026-10-03T06:17:36.025070+00:00</updated>
    <content>bdu:2024-04110</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-if32046</id>
    <title>Withdrawn: CLEANSTART-2026-IF32046 — Security fixes in local-static-provisioner 2.6.0-r1</title>
    <updated>2026-10-03T06:17:36.025111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: local-static-provisioner</p>
<p>Package local-static-provisioner version 2.6.0-r1 fixes 18 vulnerabilities: ghsa-7fxm-f474-hf8w, ghsa-q78c-gwqw-jcmc, CVE-2023-3676, CVE-2023-3955, ghsa-hq6q-c2x6-hmch...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-if32046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-24974</id>
    <title>cnvd-2024-24974</title>
    <updated>2026-10-03T06:17:36.025147+00:00</updated>
    <content>cnvd-2024-24974</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-24974"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-162496</id>
    <title>EUVD-2026-162496</title>
    <updated>2026-10-03T06:17:36.025162+00:00</updated>
    <content>EUVD-2026-162496</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-162496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3177</id>
    <title>fkie_cve-2024-3177</title>
    <updated>2026-10-03T06:17:36.025174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-3177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pxhw-596r-rwq5</id>
    <title>GHSA-pxhw-596r-rwq5 — Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin</title>
    <updated>2026-10-03T06:17:36.025203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: k8s.io/kubernetes</p>
<p>A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pxhw-596r-rwq5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-3177</id>
    <title>gsd-2024-3177</title>
    <updated>2026-10-03T06:17:36.025230+00:00</updated>
    <content>gsd-2024-3177</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-3177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-3177</id>
    <title>msrc_CVE-2024-3177 — Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin</title>
    <updated>2026-10-03T06:17:36.025242+00:00</updated>
    <content>msrc_CVE-2024-3177</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-3177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1550</id>
    <title>OESA-2024-1550 — kubernetes security update</title>
    <updated>2026-10-03T06:17:36.025257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: kubernetes</p>
<p>Container cluster management.

Security Fix(es):

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

(CVE-2024-3177)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0043</id>
    <title>RHSA-2024:0043 — Red Hat Security Advisory: Red Hat build of MicroShift 4.16.0 security update</title>
    <updated>2026-10-03T06:17:36.025281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubernetes: kube-apiserver: bypassing mountable secrets policy imposed by the ServiceAccount admission plugin golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1403-1</id>
    <title>SUSE-SU-2024:1403-1 — Security update for kubernetes1.24</title>
    <updated>2026-10-03T06:17:36.025300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for kubernetes1.24</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1403-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3177</id>
    <title>Withdrawn: UBUNTU-CVE-2024-3177</title>
    <updated>2026-10-03T06:17:36.025315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes</p>
<p>A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0904</id>
    <title>WID-SEC-W-2024-0904 — Kubernetes: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T06:17:36.025341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0904"/>
  </entry>
</feed>
