-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/fabedge/fabedge | go | <= 0.8.1 |
The vulnerability stems from insecure RBAC configurations and token handling. The provided PoC demonstrates attackers abusing over-permissive ClusterRoles (CWE-863) to manipulate node scheduling and extract tokens. While no specific Go functions are explicitly named in available sources, Kubernetes manifests defining ClusterRoles with 'update/patch' on nodes and access to secrets are the root cause. The medium confidence for pod templates reflects the lack of explicit evidence about token mounting in fabedge's manifests, though this is a common vector in Kubernetes privilege escalation scenarios.
Ongoing coverage of React2Shell