There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6fg2-hvj9-832f piraeus-operator allows attacker to impersonate service account
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T02:27:53.612Z

Reserved: 2024-04-23T00:00:00

Link: CVE-2024-33398

cve-icon Vulnrichment

Updated: 2024-05-15T16:20:54.547Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-03T16:15:11.393

Modified: 2024-11-21T09:16:53.090

Link: CVE-2024-33398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses