Impact
kcp’s front‑proxy fails to remove inbound X‑Remote‑User, X‑Remote‑Group, and X‑Remote‑Extra‑* identity headers before passing a request to a shard. An authenticated tenant can therefore inject an X‑Remote‑Group header of system:masters or other privileged groups, as well as warrant, scope, or workspace‑specific gating groups. Because the shard trusts these headers as true identity assertions, the attacker is able to impersonate the system:masters group, bypass workspace authorisation controls, and arbitrarily read, write, or delete any resource, including secrets, RBAC objects, APIExports, APIBindings, and LogicalClusters.
Affected Systems
kcp by kcp‑dev, versions older than 0.31.4 and 0.32.2 are affected. These are Kubernetes‑like control planes that honour inbound identity headers for shard requests.
Risk and Exploitability
The vulnerability carried a CVSS score of 9.9, indicating critical severity. EPSS score of <1% indicates a very low probability of exploitation, but the lack of remediation in the KEV catalog suggests it may not yet be widely exploited. Inferred from the description, the attack vector is network‑based, requiring only an authenticated client to send crafted headers across the front‑proxy to a shard. Once the headers are accepted, the attacker can gain system‑wide privileges across multiple workspaces with zero additional effort. The high impact combined with the openness of the mechanism makes this a serious risk for any kcp deployment that has not applied the available fixes.
OpenCVE Enrichment
Github GHSA