The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on `open-feature-operator-controller-manager` to escalate the privileges of any SA in the cluster. The increased privileges could be used to modify cluster state, leading to DoS, or read sensitive data, including secrets. Version 0.2.32 mitigates this issue by restricting the resources the `open-feature-operator-controller-manager` can modify.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-04-14T18:47:03.747Z

Updated: 2024-08-02T14:00:14.661Z

Reserved: 2023-03-29T17:39:16.144Z

Link: CVE-2023-29018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-14T19:15:09.187

Modified: 2023-04-25T14:25:04.857

Link: CVE-2023-29018

cve-icon Redhat

No data.