Impact
During a ManagedClusterMigration, the Multicluster Global Hub mistakenly grants all managed hubs read access to a shared communication topic. This mis‑configured ACL allows a compromised hub to intercept and collect the sensitive bootstrap kubeconfigs that embed API‑server tokens meant for other hubs. The weakness is a failure of access control that exposes user credentials (CWE-522), leading to sensitive information leakage. Those tokens have an unusually long validity period, approximately nine and a half years, amplifying the potential damage if accessed by an attacker.
Affected Systems
The issue affects the Red Hat Multicluster Global Hub platform. Specific version details are not listed in the advisory, so any instance of the product lacking a documented patch may be vulnerable until a fixed release is issued.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate risk. The EPSS score is unavailable, so the likelihood of exploitation cannot be precisely quantified. Attackers would need to control a managed hub and trigger a ManagedClusterMigration to gain read access to the spec‑topic, after which they could capture bootstrap kubeconfigs. No KEV listing indicates that there is no known large‑scale exploitation reported.
OpenCVE Enrichment