Impact
An authorization bypass flaw in the provider‑credential‑controller component of Red Hat Multicluster Engine for Kubernetes allows an attacker with specific hub‑cluster permissions and knowledge of a prior credential value to manipulate copiedFrom labels. By doing so the attacker can intercept newly rotated provider credentials, resulting in unauthorized disclosure of sensitive credential information.
Affected Systems
Red Hat Multicluster Engine for Kubernetes. No specific affected version range is provided in the advisory.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting a low to moderate likelihood of exploitation. Successful exploitation requires deliberate permission settings on the hub cluster and prior knowledge of a credential value, limiting the attack surface but still enabling an attacker to gain confidential credentials if they can craft the copiedFrom labels.
OpenCVE Enrichment