{"id":"CVE-2024-33396","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-33396","summary":"An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.","details":"An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.","published":"2024-05-02T19:15:06.117","modified":"2026-06-17T07:31:43.970","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://gist.github.com/HouqiyuA/2b56a893c06553013982836abb77ba50"},{"type":"WEB","url":"https://gist.github.com/HouqiyuA/2b56a893c06553013982836abb77ba50"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T07:31:43.970"}}