Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources. By abusing these permissions, an attacker able to authenticate as the karmada-agent to a karmada cluster would be able to obtain administrative privileges over the entire federation system including all registered member clusters. Since Karmada v1.12.0, command `karmadactl register` restricts the access permissions of pull mode member clusters to control plane resources. This way, an attacker able to authenticate as the karmada-agent cannot control other member clusters in Karmada. As a workaround, one may restrict the access permissions of pull mode member clusters to control plane resources according to Karmada Component Permissions Docs.
28/08/2024 CVE-2024-42995 high
Vtiger CRM <= 8.1.0 does not correctly check user's privileges. A low-privileged user can interact directly with the `Migration` administrative module to disable arbitrary modules in the instance.
Vtiger CRM <= 8.1.0 has a SQL injection vulnerability in the MailManager module.
15/07/2024 CVE-2024-38496 medium
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
15/07/2024 CVE-2024-38495 medium
A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
15/07/2024 CVE-2024-36458 medium
The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.
15/07/2024 CVE-2024-38493 medium
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
15/07/2024 CVE-2024-38492 critical
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
15/07/2024 CVE-2024-38494 high
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
15/07/2024 CVE-2024-38491 high
The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.