Impact
A flaw in the Submariner component allows a malicious cluster to redirect traffic from peer clusters by creating a fake network endpoint that declares arbitrary subnet ranges. Because the Submariner service does not validate the endpoint.spec.subnets field, an attacker can publish an endpoint that causes all traffic destined for the declared ranges to be routed through the attacker’s tunnel, leading to unauthorized data exposure or network disruption.
Affected Systems
The vulnerability impacts Red Hat Advanced Cluster Management for Kubernetes 2.x, specifically the Submariner component included in that product. All installations of the 2.x series are potentially affected until the fix is applied.
Risk and Exploitability
The CVSS score of 2.5 indicates a low quantifiable severity, and the EPSS score of less than 1% suggests a low probability of exploitation. However, the vulnerability can be exploited by any cluster that has already been compromised or is intentionally malicious, allowing it to publish arbitrary subnets via Submariner. The absence from the KEV catalog does not reduce risk; the attack vector is through the network layer and requires the attacker to control a spoke cluster.
OpenCVE Enrichment