CVE-2024-28917

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
09/04/2024
Last modified:
07/01/2025

Description

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:* 1.0.0 (including) 5.0.5 (excluding)
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.2620-162 (excluding)
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:* 1.0.0 (including) 1.5.2 (excluding)
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:* 0.3.0-preview (excluding)
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:* 1.0.0 (including) 5.1.3 (excluding)
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:* 1.0.0 (including) 1.2.6 (excluding)
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:* 1.0.0 (including) 1.1.2 (excluding)