CVE-2024-39690 | Capsule tenant owner with "patch namespace" permission can hijack system namespaces
Exp
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch.
Conclusion & alert: CVE-2024-39690 is rated High Exploit Risk (62.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.51%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2024-39690
Exploit prediction scoring system (EPSS) score for CVE-2024-39690
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).