Impact
A cross-namespace authorization flaw in multicluster-ob modify a ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add‑on may copy the referenced Secrets to the attacker‑controlled managed cluster, resulting in an unauthorized disclosure of confidential data (CWE‑551).
Affected Systems
The affected product is Red Hat Advanced Cluster Management for Kubernetes version 2. No specific sub‑versions are listed, so all releases in the 2.x line are potentially impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. The EPSS score of <1 % indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Explo a ManagedClusterAddOn configuration on a managed cluster and then reference hub resources, thereby exposing confidential Secrets to the attacker’s managed cluster and compromising confidentiality.
OpenCVE Enrichment