<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:53:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04110</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04110</link>
      <description>bdu:2024-04110</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04110</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-IF32046 — Security fixes in local-static-provisioner 2.6.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-if32046</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: local-static-provisioner&lt;/p&gt;
&lt;p&gt;Package local-static-provisioner version 2.6.0-r1 fixes 18 vulnerabilities: ghsa-7fxm-f474-hf8w, ghsa-q78c-gwqw-jcmc, CVE-2023-3676, CVE-2023-3955, ghsa-hq6q-c2x6-hmch...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: local-static-provisioner&lt;/p&gt;
&lt;p&gt;Package local-static-provisioner version 2.6.0-r1 fixes 18 vulnerabilities: ghsa-7fxm-f474-hf8w, ghsa-q78c-gwqw-jcmc, CVE-2023-3676, CVE-2023-3955, ghsa-hq6q-c2x6-hmch...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-if32046</guid>
    </item>
    <item>
      <title>cnvd-2024-24974</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-24974</link>
      <description>cnvd-2024-24974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-24974</guid>
    </item>
    <item>
      <title>EUVD-2026-162496</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-162496</link>
      <description>EUVD-2026-162496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-162496</guid>
    </item>
    <item>
      <title>fkie_cve-2024-3177</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3177</link>
      <description>&lt;p&gt;A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-3177</guid>
    </item>
    <item>
      <title>GHSA-pxhw-596r-rwq5 — Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pxhw-596r-rwq5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: k8s.io/kubernetes&lt;/p&gt;
&lt;p&gt;A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: k8s.io/kubernetes&lt;/p&gt;
&lt;p&gt;A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pxhw-596r-rwq5</guid>
    </item>
    <item>
      <title>gsd-2024-3177</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-3177</link>
      <description>gsd-2024-3177</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-3177</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-3177 — Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-3177</link>
      <description>msrc_CVE-2024-3177</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-3177</guid>
    </item>
    <item>
      <title>OESA-2024-1550 — kubernetes security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1550</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kubernetes&lt;/p&gt;
&lt;p&gt;Container cluster management.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&#13;
&#13;
(CVE-2024-3177)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kubernetes&lt;/p&gt;
&lt;p&gt;Container cluster management.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&#13;
&#13;
(CVE-2024-3177)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1550</guid>
    </item>
    <item>
      <title>RHSA-2024:0043 — Red Hat Security Advisory: Red Hat build of MicroShift 4.16.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0043</link>
      <description>&lt;p&gt;kubernetes: kube-apiserver: bypassing mountable secrets policy imposed by the ServiceAccount admission plugin golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kubernetes: kube-apiserver: bypassing mountable secrets policy imposed by the ServiceAccount admission plugin golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0043</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1403-1 — Security update for kubernetes1.24</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1403-1</link>
      <description>&lt;p&gt;Security update for kubernetes1.24&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubernetes1.24&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1403-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-3177</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3177</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes&lt;/p&gt;
&lt;p&gt;A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes&lt;/p&gt;
&lt;p&gt;A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3177</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0904 — Kubernetes: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0904</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0904</guid>
    </item>
  </channel>
</rss>
