← Back to browse · API

CVE-2024-36532

Severity
CRITICAL
CVSS
10.0
EPSS
0.00452
Risk score
40.16
CISA KEV
No
PoC
No
Published
2024-06-21
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-36146, GHSA-95JF-85V4-5P6V
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-36146

Description

Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

References