Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
References
| Link | Resource |
|---|---|
| https://gist.github.com/HouqiyuA/f06d1fa07b5287b862c1e0b288f301e5 | Third Party Advisory Exploit |
| https://gist.github.com/HouqiyuA/f06d1fa07b5287b862c1e0b288f301e5 | Third Party Advisory Exploit |
Configurations
History
No history.
Information
Published : 2024-07-24 19:15
Updated : 2025-10-14 14:41
NVD link : CVE-2024-36538
Mitre link : CVE-2024-36538
CVE.ORG link : CVE-2024-36538
JSON object : View
Products Affected
chaos-mesh
- chaos_mesh
CWE
CWE-278
Insecure Preserved Inherited Permissions
