{"id":"CVE-2024-56513","aliases":["GHSA-mg7w-c9x2-xh7r","GO-2025-3364"],"url":"https://o3.security/vulnerability/CVE-2024-56513","summary":"Karmada PULL Mode Cluster Privilege Escalation","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nThe [PULL](https://karmada.io/docs/next/userguide/clustermanager/cluster-registration#pull-mode) mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources. By abusing these permissions, an attacker able to authenticate as the karmada-agent to a karmada cluster would be able to obtain administrative privileges over the entire federation system including all registered member clusters.\n\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nSince Karmada v1.12.0, command `karmadactl register` restricts the access permissions of pull mode member clusters to control plane resources. This way, an attacker able to authenticate as the karmada-agent cannot control other member clusters in Karmada.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nRestricts the access permissions of pull mode member clusters to control plane resources according to [Karmada Component Permissions Docs](https://karmada.io/docs/administrator/security/component-permission).\n### References\n_Are there any links users can visit to find out more?_\n 1. Enhancements made from the Karmada community: https://github.com/karmada-io/karmada/pull/5793\n 2. Karmada Component Permissions: https://karmada.io/docs/administrator/security/component-permission\n","published":"2025-01-03T16:11:51.629Z","modified":"2026-08-12T03:51:48.479096569Z","cvss":null,"epss":{"score":0.00494,"percentile":0.3982,"asOf":"2026-08-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/karmada-io/karmada","fixedVersion":"1.12.0"}],"fix":{"url":"https://github.com/karmada-io/karmada/commit/2c82055c4c7f469411b1ba48c4dba4841df04831","label":"karmada-io/karmada@2c82055"},"references":[{"type":"WEB","url":"https://karmada.io/docs/administrator/security/component-permission"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56513.json"},{"type":"ADVISORY","url":"https://github.com/karmada-io/karmada/security/advisories/GHSA-mg7w-c9x2-xh7r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56513"},{"type":"FIX","url":"https://github.com/karmada-io/karmada/commit/2c82055c4c7f469411b1ba48c4dba4841df04831"},{"type":"FIX","url":"https://github.com/karmada-io/karmada/pull/5793"},{"type":"PACKAGE","url":"https://github.com/karmada-io/karmada"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.479096569Z"}}