CVE

CVE-2024-36540

Severity:
CRITICAL
Type:
CWE-284 Improper Access Control
Publication date:
24/07/2024
Last modified:
01/08/2024

Description

Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

References to Advisories, Solutions, and Tools