---
id: CVE-2024-5042
title: A flaw was found in the Submariner project
summary: >-
  A flaw was found in the Submariner project. Due to unnecessary role-based
  access control permissions, a privileged attacker can run a malicious
  container on a node that may allow them to steal service account tokens and
  further compromis…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N'
cwe:
  - CWE-250
vendor: Red Hat
product: submariner-operator
affected:
  - submariner-operator < 0.14.9
  - submariner-operator >= 0.15.0 < 0.15.5
  - submariner-operator >= 0.16.0 < 0.16.7
  - submariner-operator >= 0.17.0 < 0.17.2
  - submariner-operator >= 0.18.0-m0 < 0.18.0-rc0
  - odf4/odf-multicluster-rhel9-operator (all versions)
  - odf4/cephcsi-rhel9 (all versions)
  - odf4/cephcsi-rhel9-operator (all versions)
  - odf4/mcg-core-rhel9 (all versions)
  - odf4/mcg-rhel9-operator (all versions)
  - odf4/ocs-client-console-rhel9 (all versions)
  - odf4/ocs-client-rhel9-operator (all versions)
  - odf4/ocs-metrics-exporter-rhel9 (all versions)
  - odf4/ocs-rhel9-operator (all versions)
  - odf4/odf-cli-rhel9 (all versions)
  - odf4/odf-cloudnative-pg-rhel9-operator (all versions)
  - odf4/odf-console-rhel9 (all versions)
  - odf4/odf-cosi-sidecar-rhel9 (all versions)
  - odf4/odf-csi-addons-rhel9-operator (all versions)
  - odf4/odf-csi-addons-sidecar-rhel9 (all versions)
  - odf4/odf-external-snapshotter-rhel9-operator (all versions)
  - odf4/odf-external-snapshotter-sidecar-rhel9 (all versions)
  - odf4/odf-multicluster-console-rhel9 (all versions)
  - odf4/odf-multicluster-rhel9-operator (all versions)
  - odf4/odf-must-gather-rhel9 (all versions)
  - odf4/odf-rhel9-operator (all versions)
  - odf4/odr-rhel9-operator (all versions)
  - odf4/rook-ceph-rhel9-operator (all versions)
  - rhacm2/lighthouse-agent-rhel9 (all versions)
  - rhacm2/lighthouse-coredns-rhel9 (all versions)
  - rhacm2/submariner-gateway-rhel8 (all versions)
  - rhacm2/submariner-globalnet-rhel9 (all versions)
  - rhacm2/submariner-rhel9-operator (all versions)
  - rhacm2/submariner-route-agent-rhel8 (all versions)
published: '2024-05-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T11:17:01.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-5042'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:4591'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:6503'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-5042'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2280921'
    label: secalert@redhat.com
  - url: 'https://github.com/advisories/GHSA-2rhx-qhxp-5jpw'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4591'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2024-5042'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2280921'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/advisories/GHSA-2rhx-qhxp-5jpw'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5042.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-5042'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-5042'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00507
epssPercentile: 0.40681
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-05-20T14:43:37.969142Z'
ingestedAt: '2026-07-18T21:25:07.041Z'
patched:
  - rhodf_4_16_for_rhel 9
  - openshift_data_foundation 4.20
---

## Overview

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:4591** · Red Hat · fixed in: RHODF 4.16 for RHEL 9 · released 2024-07-17 · [advisory](https://access.redhat.com/errata/RHSA-2024:4591)
- **RHSA-2026:6503** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.20 · released 2026-04-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:6503)
- **Red Hat VEX** · Moderate · affected: Red Hat Advanced Cluster Management for Kubernetes 2 · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-5042.json)
