Description

A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted FenceAgentsRemediation for a fence agent supportingĀ  --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This RCE leads to a privilege escalation, first as the service account running the operator, then to another service account with cluster-admin privileges.

INFO

Published Date :

2024-08-12T05:46:16.035Z

Last Modified :

2026-02-25T20:31:25.618Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-5651 vulnerability.

Vendors Products
Redhat
  • Workload Availability Far
  • Workload Availability Fence Agents Remediation

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact