Impact
The flaw arises from configuring the validating webhook’s finalize rule with the singular resource name namespace/finalize instead of the correct plural form namespaces/finalize in the configuration file for Capsule 0.13.0 through 0.13.6. Because the webhook regex never matches the plural namespace/finalize resource, an attacker granted RBAC on namespaces/finalize can issue an authenticated PUT to /api/v1/namespaces/{namespace}/finalize, bypassing the webhook and changing the namespace tenant label. MatchPolicy: Equivalent, which only addresses API group and version equivalence, does not correct resource-name errors. This allows cross‑tenant data exposure or privilege escalation by reassigning a namespace to an unintended tenant.
Affected Systems
ProjectCapsule Capsule is vulnerable in all releases from version 0.13.0 up through 0.13.5. The bug was corrected in 0.13.6 and later.
Risk and Exploitability
The CVSS score of 5.7 classifies the issue as moderate in severity. The EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited. Nevertheless, the vulnerability permits an attacker who already has RBAC rights on the namespaces/finalize resource to modify tenant labels, effectively bypassing tenant isolation and potentially enabling privilege escalation. Exploitation requires only normal authenticated API calls to the Kubernetes namespace finalize endpoint and does not necessitate elevated privileges beyond those already granted by RBAC.
OpenCVE Enrichment
Github GHSA