VDB
CVE-2024-36537
CVE-2024-36537
PUBLISHED
CVSS 7.199999809265137 HIGH
Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
EPSS 0.45% · 37.0th percentile
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.45%
37.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | cert-manager | 1.14.4 |
| Bitnami | cert-manager | 1.14.4, 1.14.4, 1.14.4 |
Timeline
- Jul 24, 2024 CVE Published
- Jul 24, 2024 PoC Published
- Jul 25, 2024 EPSS Score
- Aug 16, 2024 EPSS Score
- Sep 6, 2024 EPSS Score
- Sep 28, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 19, 2024 EPSS Score
- Nov 10, 2024 EPSS Score
- Dec 3, 2024 EPSS Score
- Dec 24, 2024 EPSS Score
- Jan 15, 2025 EPSS Score