Impact
Eclipse Ankaios versions v0.5.1 through v1.0.1 contain an authorization flaw where the Control Interface authoriser incorrectly matches multi‑segment allow rules whose first segment is a wildcard. An authenticated workload restricted by such a rule can send a CompleteStateRequest or UpdateStateRequest with an empty field mask. The request may be incorrectly authorised, permitting the workload to read the entire cluster state or alter state outside its intended subtree, leading to disclosure or modification of other workloads and cluster configuration. This flaw is a classic example of a broken authorization logic (CWE‑863).
Affected Systems
The affected product is Eclipse Ankaios, part of the Eclipse Foundation. Vulnerable versions are v0.5.1 through v1.0.1. Versions released after v1.0.1, including the official v1.0.2 update, contain the fix.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is an authenticated workload within the cluster that is permitted to submit state requests. If such a workload is compromised or misconfigured, the attacker can gain broader access to cluster state and configuration. Given the high impact of full‑state disclosure or modification, the risk is significant even though exploitation probability data is missing.
OpenCVE Enrichment