blob: 2ea116571dd57fb5417af3eba34d5db6baf35e5d [file] [log] [blame]
id: GO-2024-3077
modules:
- module: github.com/projectcapsule/capsule
unsupported_versions:
- last_affected: 0.7.0
vulnerable_at: 0.7.0
summary: |-
Capsule tenant owner with "patch namespace" permission can hijack system
namespaces in github.com/projectcapsule/capsule
cves:
- CVE-2024-39690
ghsas:
- GHSA-mq69-4j5w-3qwp
references:
- advisory: https://github.com/projectcapsule/capsule/security/advisories/GHSA-mq69-4j5w-3qwp
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-39690
- fix: https://github.com/projectcapsule/capsule/commit/d620b0457ddec01616b8eab8512a10611611f584
source:
id: GHSA-mq69-4j5w-3qwp
created: 2024-08-21T10:26:09.725236-04:00
review_status: UNREVIEWED