Impact
The vulnerability resides in volsync-addon-controller, where annotation values are rendered into YAML templates without proper escaping. This flaw enables an attacker to inject malicious YAML code into the OpenShift Lifecycle Manager Subscription resource. The injection can alter subscription configurations, potentially granting unauthorized control over software management processes within the cluster.
Affected Systems
The affected system is Red Hat Advanced Cluster Management for Kubernetes version 2. The flaw occurs when the volsync‑addon‑deploy‑type annotation is explicitly set to olm.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires access to the cluster to supply the malicious annotation, meaning exploitation would be limited to insider or compromised credentials. Despite the moderate score, the potential to subvert OLM subscription management warrants timely mitigation.
OpenCVE Enrichment