Impact
A flaw in the multicloud-integration component of Red Hat Advanced Cluster Management for Kubernetes 2 lets an authenticated tenant manipulate the GitOpsCluster controller. By doing so, the tenant can redirect bearer tokens that are normally stored in secure locations to a namespace under the tenant’s control. This allows the tenant to read sensitive tokens that authenticate to spoke clusters, potentially revealing critical information and bypassing ArgoCD AppProject security policies. The weakness is a form of credential or token storage mismanagement (CWE-441).
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes version 2. No other vendors or products are listed as affected.
Risk and Exploitability
The attacker’s primary vector is an authenticated tenant acting inside the cluster, manipulating the GitOpsCluster controller to redirect bearer tokens. The vulnerability’s impact is unauthorized disclosure of tokens that can authenticate to spoke clusters. The CVSS score of 9.6 reflects a severe threat, yet the EPSS score of <1% indicates a very low likelihood of exploitation. Although the CVE is not listed in the CISA KEV catalog, the weakness still requires remediation.
OpenCVE Enrichment