Impact
A flaw in the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes allows a cluster administrator or any user with permission to modify the Submariner Custom Resource to specify an unvalidated image path. The lack of validation permits an attacker to deploy a malicious image, which results in arbitrary code execution with elevated privileges across all cluster nodes, including control‑plane nodes. This vulnerability is an instance of improper input validation (CWE‑20) and enables full cluster compromise when exploited.
Affected Systems
The Red Hat Advanced Cluster Management for Kubernetes product, version 2, is affected through its submariner‑operator component. The exact version range is not specified, so all current installments of Red Hat Advanced Cluster Management for Kubernetes 2 that include the submariner‑operator should be considered vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and while the EPSS score is < 1%, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to have cluster‑admin level permissions or the ability to modify Submariner Custom Resources. Once those privileges are obtained, the attacker can override the image field and achieve code execution with cluster‑wide privileges. Because accessing the image override requires privileged roles, exploitation is limited to compromised or malicious insiders rather than remote attackers with no authentication.
OpenCVE Enrichment