{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T19:19:04.627","vulnerabilities":[{"cve":{"id":"CVE-2024-45496","sourceIdentifier":"secalert@redhat.com","published":"2024-09-17T00:15:52.433","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container."},{"lang":"es","value":"Se encontró una falla en OpenShift. Este problema ocurre debido al uso indebido de privilegios elevados en el proceso de compilación de OpenShift Container Platform. Durante el paso de inicialización de la compilación, el contenedor git-clone se ejecuta con un contexto de seguridad privilegiado, lo que permite un acceso sin restricciones al nodo. Un atacante con acceso de nivel de desarrollador puede proporcionar un archivo .gitconfig diseñado que contenga comandos ejecutados durante el proceso de clonación, lo que lleva a la ejecución arbitraria de comandos en el nodo de trabajo. Un atacante que ejecute código en un contenedor privilegiado podría aumentar sus permisos en el nodo que ejecuta el contenedor."}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":6.0}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2024:3718","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6685","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6687","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6689","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6691","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6705","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-45496","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2308661","source":"secalert@redhat.com"}]}}]}