VYPR
High severity8.4NVD Advisory· Published May 2, 2024· Updated Apr 15, 2026

CVE-2024-33396

CVE-2024-33396

Description

An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/karmada-io/karmadaGo
<= 1.9.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.