Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-28917: Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

According to the CVSS metric, Confidentiality is high (C:H) but integrity is none (I:N) and availability is none (A:N). What does that mean for this vulnerability?

An attacker who successfully exploited this vulnerability could gain access to sensitive information such as Azure IoT Operations secrets and potentially other credentials or access tokens stored within the Kubernetes cluster.

Microsoft Security Response Center
#vulnerability#kubernetes#Azure Arc#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-10488: Chromium: CVE-2024-10488 Use after free in WebRTC