{"api_version":"1","generated_at":"2026-07-23T13:24:19+00:00","cve":"CVE-2024-32359","urls":{"html":"https://cve.report/CVE-2024-32359","api":"https://cve.report/api/cve/CVE-2024-32359.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-32359","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-32359"},"summary":{"title":"CVE-2024-32359","description":"An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.","state":"PUBLISHED","assigner":"mitre","published_at":"2024-05-02 16:15:08","updated_at":"2026-07-09 01:19:01"},"problem_types":["CWE-285","n/a","CWE-285 CWE-285 Improper Authorization"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"6.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","data":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"6.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"HIGH"}}],"references":[{"url":"https://github.com/carina-io/carina","name":"https://github.com/carina-io/carina","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906","name":"https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/HouqiyuA/k8s-rbac-poc","name":"https://github.com/HouqiyuA/k8s-rbac-poc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://carina.com","name":"http://carina.com","refsource":"MITRE","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-32359","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32359","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]},{"source":"ADP","vendor":"carina","product":"carina","version":"affected *","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2024","cve_id":"32359","cve":"CVE-2024-32359","epss":"0.002250000","percentile":"0.131340000","score_date":"2026-07-13","updated_at":"2026-07-14 00:13:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"cpes":["cpe:2.3:a:carina:carina:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"carina","vendor":"carina","versions":[{"status":"affected","version":"*"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2024-32359","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2024-05-16T17:57:48.829205Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"CWE-285 Improper Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2024-06-04T17:50:40.310Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-07-09T00:30:53.893Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://github.com/HouqiyuA/k8s-rbac-poc"},{"tags":["x_transferred"],"url":"https://github.com/carina-io/carina"},{"tags":["x_transferred"],"url":"https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2026-07-05T00:39:30.294Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"url":"https://github.com/HouqiyuA/k8s-rbac-poc"},{"url":"https://github.com/carina-io/carina"},{"url":"https://gist.github.com/HouqiyuA/568d9857dab4ddba6b8b6a791e90f906"}]}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2024-32359","datePublished":"2024-05-02T00:00:00.000Z","dateReserved":"2024-04-12T00:00:00.000Z","dateUpdated":"2026-07-09T00:30:53.893Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-05-02 16:15:08","lastModifiedDate":"2026-07-09 01:19:01","problem_types":["CWE-285","n/a","CWE-285 CWE-285 Improper Authorization"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.4,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-16T17:57:48.829205Z","id":"CVE-2024-32359","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"32359","Ordinal":"1","Title":"CVE-2024-32359","CVE":"CVE-2024-32359","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"32359","Ordinal":"1","NoteData":"An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.","Type":"Description","Title":"CVE-2024-32359"}]}}}