Open-cluster-management-io/ocm: cluster-manager permissions may allow a worker node to obtain service account tokens
Published Dec 17, 2024
7.5
HIGHCVSS 3.1
EPSS 0.44%
Description
A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which includes the permission to create Pod resources. If this deployment runs a pod on an attacker-controlled node, the attacker can obtain the cluster-manager's token and steal any service account token by creating and mounting the target service account to control the whole cluster.
Affected products
No data.
No data.
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
open-cluster-management
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | open-cluster-management | Not affected | n/a |
open-cluster-management.io/ocm
Go
Introduced 0 Fixed 0.13.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | open-cluster-management.io/ocm | 0 | 0.13.0 |
Remediation
Red Hat statement
This flaw affects upstream Open Cluster Management version 0.12.0 and was fixed in 0.13.0. No supported versions of Red Hat Advanced Cluster Management are affected.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 18, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.44% (0.00438) | 35.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00431) | 34.19th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00061) | 16.14th | v4 (v2025.03.14) |
| Dec 18, 2024 | 0.05% (0.00054) | 24.55th | v3 (v2023.03.01) |
References (8)
- https://access.redhat.com/security/cve/CVE-2024-9779 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2317916 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-jhh6-6fhp-q2xp Advisory
- https://github.com/open-cluster-management-io/ocm/pull/325
- https://github.com/open-cluster-management-io/ocm/releases/tag/v0.13.0
- https://github.com/open-cluster-management-io/registration-operator/issues/361
- https://nvd.nist.gov/vuln/detail/CVE-2024-9779
- https://www.cve.org/CVERecord?id=CVE-2024-9779
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-9779 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2317916 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-jhh6-6fhp-q2xp | Advisory | |
| https://github.com/open-cluster-management-io/ocm/pull/325 | ||
| https://github.com/open-cluster-management-io/ocm/releases/tag/v0.13.0 | ||
| https://github.com/open-cluster-management-io/registration-operator/issues/361 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-9779 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-9779 |
Change history (0)
No recorded changes yet.