CVE-2024-7598 is a low-severity security flaw in Kubernetes where a malicious pod could temporarily bypass network policy restrictions during namespace deletion. This occurs because network policies might be deleted before the pods they protect, creating a brief window of un-enforced network access. The vulnerability has a CVSS score of 3.1 (LOW) with an adjacent attack vector and high attack complexity, resulting in a potential low impact on confidentiality. There is no known active exploitation, public exploit code, or KEV listing, though it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kubernetes | Kube-Apiserver | 1.3.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Kubernetes kube-apiserver Vulnerable to Race Condition
Mar 20, 2025kube-apiserver: Network restriction bypass via race condition during namespace termination
Mar 20, 2025Network restriction bypass via race condition during namespace termination
Mar 11, 2025Network restriction bypass via race condition during namespace termination
Network restriction bypass via race condition during namespace termination
Network restriction bypass via race condition during namespace termination
Network restriction bypass via race condition during namespace termination