A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
CVE ID: CVE-2024-5042
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 17.98% (scored less or equal to compared to others)
EPSS Date: 2025-02-18 (when was this score calculated)