Impact
Strimzi 1.0.0 and earlier provide the Entity Operator ServiceAccount with RBAC permissions for both the Topic Operator and the User Operator, even when only one component is enabled via the Kafka custom resource. This over‑permissive policy allows the ServiceAccount to read KafkaUser custom resources and the Secrets associated with them when the User Operator is not deployed, or to read KafkaTopic custom resources when the Topic Operator is absent. Attackers can exploit this to retrieve sensitive configuration data, such as connection credentials, from Secrets stored in the namespace. The flaw constitutes an authorization bypass that compromises confidentiality of data within the namespace, potentially affecting multiple users or applications consuming those secrets.
Affected Systems
The vulnerability affects Strimzi Kafka Operator versions 1.0.0 and earlier. When deploying only the Topic Operator or only the User Operator through the Kafka custom resource, the Entity Operator ServiceAccount retains permissions for both components. The fix is available in releases 1.0.1 and 1.1.0.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate impact and complexity. EPSS is reported as less than 1%, suggesting a low probability of active exploitation. The CVE is not listed in the CISA KEV catalog. An attacker must be able to access a pod or process that has the Entity Operator ServiceAccount token within the same namespace. By using that token, the attacker can read Secret objects and custom resources, potentially exposing sensitive information to any user or application with that token.
OpenCVE Enrichment
Github GHSA