Impact
A flaw in the search-v2-operator component of Red Hat Advanced Cluster Management for Kubernetes 2 permits a user with certain administrative permissions on a managed cluster to inject arbitrary configuration data. The injected data can override critical settings, ultimately resulting in the replacement of container images and thereby compromising the cluster’s image integrity.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2 is affected. Specific affected version ranges are not listed; any instance of version 2 of the product could potentially expose the vulnerability.
Risk and Exploitability
The vulnerability is scored as CVSS 8.5, indicating high severity, and is not currently listed in the CISA KEV catalog. The EPSS score is unavailable, leaving exact exploit likelihood uncertain. The attack vector is privilege‑based: a user who already has specific administrative rights on a managed cluster can exploit the flaw by using the addonfactory.getvaluesfromaddonannotation functionality to override helm values. Because the flaw enables container image injection, the risk to confidentiality, integrity, and availability is significant for affected clusters.
OpenCVE Enrichment