A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-12-18T13:43:07.807Z

Updated: 2024-09-16T13:53:32.105Z

Reserved: 2023-09-18T18:33:13.584Z

Link: CVE-2023-5056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-18T14:15:10.133

Modified: 2023-12-29T18:14:30.437

Link: CVE-2023-5056

cve-icon Redhat

Severity : Important

Publid Date: 2023-10-26T14:58:00Z

Links: CVE-2023-5056 - Bugzilla