CVE-2024-42480 | Kamaji's RBAC Roles for `etcd` are not disjunct
Exp
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.
Conclusion & alert: CVE-2024-42480 is rated High Exploit Risk (63.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.62%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2024-42480
Exploit prediction scoring system (EPSS) score for CVE-2024-42480
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).