Impact
The CVE record provides no detailed description, yet the title points to a transport‑layer man‑in‑the‑middle vulnerability where multicluster‑global‑hub retrieves a TLS CA bundle from an unvalidated ConfigMap and may fall back to InsecureSkipVerify. This situation is classified as CWE‑295, indicating improper certificate validation at the transport layer.
Affected Systems
The vulnerability impacts the multicluster-global-hub component. No vendor, product version or patch information is supplied, so any deployment of this component could be affected.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is currently no evidence of widespread active exploitation. Based on the nature of the weakness (TLS certificate validation), an attacker who can influence the ConfigMap used by the component might be able to insert a bogus CA bundle and intercept or tamper with traffic, but the exact attack path is not detailed in the available data.
OpenCVE Enrichment