CVE-2024-36533

CRITICAL Year: 2024
CVSS v3 Score
9.8
Critical

Vulnerability Description

Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

CVSS:6.3(Medium)

KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The JWT key in the default configuration file is empty. Although a ...

CVSS:5.0(Medium)

biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token ...