Impact
The Konnectivity proxy‑server was configured to start its agent‑facing listener without requiring a cluster CA certificate or token‑based authentication, which means client certificates were not validated. This flaw allows a remote attacker who can reach the Konnectivity cluster endpoint to connect as an unauthenticated agent, join the routing pool, and gain a path through which control‑plane‑to‑node traffic can be proxied, inspected, modified, or dropped. The vulnerability is identified as CWE‑306, Improper Authentication.
Affected Systems
Red Hat products affected include Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat Multicluster Engine for Kubernetes (including version 2.10), and Red Hat OpenShift API for Data Protection. Specific versions are not enumerated, so any deployment using the affected components with the Konnectivity plugin may be vulnerable.
Risk and Exploitability
The CVSS score of 9.4 classifies the vulnerability as critical, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. A threat actor who can reach the Konnectivity cluster endpoint can establish an unauthenticated agent session, insert themselves into the routing service, and thereby manipulate traffic between the control plane and cluster nodes. No further impact claims beyond this mechanism are stated in the provided description.
OpenCVE Enrichment