CVE-2024-33522 is a privilege escalation vulnerability affecting Calico, Calico Enterprise, and Calico Cloud versions. An attacker with local access to a Kubernetes node can exploit an incorrectly configured SUID bit in the Calico CNI install binary to execute arbitrary code with elevated privileges. This vulnerability has a CVSS score of 6.7 (Medium), indicating a local attack vector with high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tigera | Calico Cloud | >= 0, < v19.3.0CNA affecteddefault unaffected | |
| Tigera | Calico Enterprise | >= 0, < v3.17.4, >= v3.18.0, < v3.18.2, >= v3.19.0-1.0, < v3.19.0-2.0CNA affecteddefault unaffected | |
| Tigera | Calico | >= 0, < v3.26.5, >= v3.27.0, < v3.27.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.