Impact
The hawtio-operator cluster role grants the ServiceAccount full secrets permissions across every namespace, including create, get, list, update and watch. The operator’s controller-runtime cache does not impede this access and further bypasses it through direct API calls. Compromise of the operator pod therefore provides an attacker read access to all cluster secrets, such as bootstrap tokens, cloud credentials and other operators’ secrets.
Affected Systems
Red Hat builds of Apache Camel – HawtIO 4 are vulnerable. No specific version numbers are listed in the CNA data.
Risk and Exploitability
The CVSS score of 8.2 reflects a high severity vulnerability. Although an EPSS score is not available, the CVE is not listed in CISA’s KEV catalog. The likely attack path involves compromising the hawtio-operator pod or exploiting an upstream weakness that gives an attacker the necessary privileges. Once the pod is compromised, the attacker can read every cluster secret, leading to potential credential leaks and further lateral movement within the cluster.
OpenCVE Enrichment