Impact
The vulnerability is a privilege‑escalation flaw in the Portworx Operator when it is deployed on Red Hat OpenShift. During the initial provisioning of a Portworx storage cluster, a user who holds only limited, namespace‑scoped permissions can manipulate the operator’s provisioning logic to grant broader access than intended. An attacker could therefore obtain elevated privileges within the Kubernetes cluster, potentially accessing or modifying resources beyond their assigned scope.
Affected Systems
This issue affects Everpure’s Portworx Operator running on Red Hat OpenShift (OCP). The flaw is only triggered under specific conditions during the first provisioning of a Portworx storage cluster. No particular operator or OpenShift version numbers are provided, so any deployment that uses the operator under these conditions is potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.7, indicating a high severity level, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, as the escalation occurs during the operator’s initial provisioning process, which requires the attacker to have at least some namespace‑scoped access to the cluster. Because the flaw arises from the operator’s provisioning logic, a successful exploit would allow a malicious namespace user to gain cluster‑wide rights, compromising confidentiality, integrity, and availability of cluster resources.
OpenCVE Enrichment