U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-7598

Change History

New CVE Received from Kubernetes 3/20/2025 1:15:37 PM

Action Type Old Value New Value
Added Description

								
							
							
						
A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before the pods that they protect. This can lead to a brief period in which the pods are running, but network policies that should apply to connections to and from the pods are not enforced.
Added CVSS V3.1

								
							
							
						
AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Added CWE

								
							
							
						
CWE-362
Added Reference

								
							
							
						
https://github.com/kubernetes/kubernetes/issues/126587
Added Reference

								
							
							
						
https://groups.google.com/g/kubernetes-security-announce/c/67D7UFqiPRc