Impact
The vulnerability arises from unsanitized data in a hub‑cluster ConfigMap that is passed directly as command‑line arguments to a privileged install Job, exemplifying an argument‑injection flaw (CWE‑88). An attacker who can write to the hypershift‑operator‑install‑flags ConfigMap can inject arbitrary arguments, causing the Job to pull malicious container images and execute code with cluster‑admin privileges on each managed spoke cluster. This results in complete administrative control over the affected clusters.
Affected Systems
This flaw affects the Hypershift Addon Operator component of the Hypershift platform. No specific product version is listed, and users should verify whether their deployed hypershift-addon-operator instance is vulnerable. The vulnerability is tied to the hypershift-operator-install-flags ConfigMap within the hub cluster.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the ability to modify the ConfigMap, and the resulting Job runs with privileged permissions, enabling the attacker to execute arbitrary code on spoke clusters. The likely attack vector is internal cluster compromise or abuse of administrative privileges.
OpenCVE Enrichment