Impact
The vulnerability occurs when the Instana Agent Operator copies etcd mTLS client credentials from the openshift‑etcd system namespace into an attacker‑controlled namespace without validating the destination. An attacker who has authenticated access to the cluster can therefore retrieve sensitive credentials that grant encryption and authentication privileges. The potential impact is the compromise of secrets that could allow further lateral movement or data exfiltration. The weakness is identified as CWE‑863, meaning an incorrect access control decision.
Affected Systems
IBM Observability with Instana (Agent) – affected builds include 1.0.303 through 1.0.323. Version 1.0.324 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.7 indicates a high likelihood of exploitation in a restricted environment. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access to the cluster, which is often scoped to privileged users or service accounts with enough privileges to run the Instana Agent Operator. The risk to confidentiality is high because the attacker can read TLS client credentials that protect etcd communications.
OpenCVE Enrichment