{"id":"CVE-2024-5042","title":"A flaw was found in the Submariner project","summary":"A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…","severity":"medium","cvss":6.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N","cwe":["CWE-250"],"vendor":"Red Hat","product":"submariner-operator","affected":["submariner-operator < 0.14.9","submariner-operator >= 0.15.0 < 0.15.5","submariner-operator >= 0.16.0 < 0.16.7","submariner-operator >= 0.17.0 < 0.17.2","submariner-operator >= 0.18.0-m0 < 0.18.0-rc0","odf4/odf-multicluster-rhel9-operator (all versions)","odf4/cephcsi-rhel9 (all versions)","odf4/cephcsi-rhel9-operator (all versions)","odf4/mcg-core-rhel9 (all versions)","odf4/mcg-rhel9-operator (all versions)","odf4/ocs-client-console-rhel9 (all versions)","odf4/ocs-client-rhel9-operator (all versions)","odf4/ocs-metrics-exporter-rhel9 (all versions)","odf4/ocs-rhel9-operator (all versions)","odf4/odf-cli-rhel9 (all versions)","odf4/odf-cloudnative-pg-rhel9-operator (all versions)","odf4/odf-console-rhel9 (all versions)","odf4/odf-cosi-sidecar-rhel9 (all versions)","odf4/odf-csi-addons-rhel9-operator (all versions)","odf4/odf-csi-addons-sidecar-rhel9 (all versions)","odf4/odf-external-snapshotter-rhel9-operator (all versions)","odf4/odf-external-snapshotter-sidecar-rhel9 (all versions)","odf4/odf-multicluster-console-rhel9 (all versions)","odf4/odf-multicluster-rhel9-operator (all versions)","odf4/odf-must-gather-rhel9 (all versions)","odf4/odf-rhel9-operator (all versions)","odf4/odr-rhel9-operator (all versions)","odf4/rook-ceph-rhel9-operator (all versions)","rhacm2/lighthouse-agent-rhel9 (all versions)","rhacm2/lighthouse-coredns-rhel9 (all versions)","rhacm2/submariner-gateway-rhel8 (all versions)","rhacm2/submariner-globalnet-rhel9 (all versions)","rhacm2/submariner-rhel9-operator (all versions)","rhacm2/submariner-route-agent-rhel8 (all versions)"],"published":"2024-05-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T11:17:01.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-5042","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:4591","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:6503","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-5042","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2280921","label":"secalert@redhat.com"},{"url":"https://github.com/advisories/GHSA-2rhx-qhxp-5jpw","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:4591","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2024-5042","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2280921","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/advisories/GHSA-2rhx-qhxp-5jpw","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5042.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-5042"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5042"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00504,"epssPercentile":0.42092,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2024-05-20T14:43:37.969142Z"},"ingestedAt":"2026-07-18T21:25:07.041Z","patched":["rhodf_4_16_for_rhel 9","openshift_data_foundation 4.20"],"slug":"CVE-2024-5042","body":"## Overview\n\nA flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2024:4591** · Red Hat · fixed in: RHODF 4.16 for RHEL 9 · released 2024-07-17 · [advisory](https://access.redhat.com/errata/RHSA-2024:4591)\n- **RHSA-2026:6503** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.20 · released 2026-04-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:6503)\n- **Red Hat VEX** · Moderate · affected: Red Hat Advanced Cluster Management for Kubernetes 2 · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5042.json)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":36.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}