Impact
A flaw in the multicloud-operators-channel component allows a user with certain permissions to unintentionally manipulate how the system handles Secrets across different namespaces. By exploiting this confusing deputy weakness (CWE-639), an attacker can alter sensitive information in unauthorized areas, potentially gaining access to confidential data or elevating privileges within the cluster.
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes 2. Specific affected versions are not listed; users should check the vendor’s advisories for applicable releases.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires the ability to create or modify a Channel resource with a spec.secretref.namespace pointing to a target namespace, so attackers need a sufficient level of access within Red Hat Advanced Cluster Management to initiate the attack path.
OpenCVE Enrichment