CVE Alert: CVE-2024-7598

Vulnerability Summary: CVE-2024-7598
A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before the pods that they protect. This can lead to a brief period in which the pods are running, but network policies that should apply to connections to and from the pods are not enforced.
Affected Endpoints:
No affected endpoints listed.
Published Date:
3/20/2025, 5:15:37 PM
❄️ CVSS Score:
Exploit Status:
Not ExploitedReferences:
- https://github.com/kubernetes/kubernetes/issues/126587
- https://groups.google.com/g/kubernetes-security-announce/c/67D7UFqiPRc
- http://www.openwall.com/lists/oss-security/2025/03/20/2
Recommended Action:
No proposed action available. Please refer to vendor documentation for updates.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.