Impact
A flaw was discovered in the clusterclaims-controller component of Multicluster Engine for Kubernetes. An authenticated tenant can manipulate ClusterClaim labels, allowing them to force a cluster to join a ManagedClusterSet that belongs to a different tenant. This unauthorized join enables the attacker to inject policies and workloads into other tenants’ clusters, potentially compromising confidentiality, integrity, and availability for those clusters.
Affected Systems
Red Hat Multicluster Engine for Kubernetes, version information not provided in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity level. EPSS information is unavailable, so no numeric estimate for exploitation probability is provided, and the issue is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated tenant, which limits exploitation to users with tenant‑level access. If exploited, the attacker could join a managed cluster to a different tenant’s ManagedClusterSet and subsequently deploy malicious policies and workloads on the target cluster.
OpenCVE Enrichment