Impact
A flaw in the multicloud-operators-subscription component allows a tenant who can create HelmRelease objects to modify the secretRef.Namespace field. By doing so, the GetSecret() function inside the HelmRelease controller retrieves sensitive credentials from any namespace and sends them to an attacker‑controlled Helm repository, exposing arbitrary namespace secrets. The primary consequence is the exfiltration of credentials, which constitutes information disclosure and can enable further compromise of cluster resources.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2, specifically the multicloud-operators-subscription component. No specific patch version is listed, so the vulnerability applies to any installation of this component in the 2.x line until a fixed release becomes available.
Risk and Exploitability
The vulnerability scores a CVSS of 7.7, indicating high severity. The EPSS score is not available, but the lack of KEV listing suggests no active exploitation reports yet. The attack requires a user with HelmRelease create permissions and cluster‑level access, making it an insider or compromised‑account vector. Once enabled, the attacker can extract any secret from any namespace and exfiltrate it to a remote repository.
OpenCVE Enrichment