Impact
A flaw in Open Cluster Management allows an agent to modify the ce-clustername header in gRPC messages, bypassing authorization checks that rely on this attribute. By providing an arbitrary cluster name, a registered cluster can masquerade as another, moving itself into other tenants' ManagedClusterSets and overwriting their ManagedCluster objects on the hub. This breach of isolation enables the attacker to receive tenant workloads, policies, and secrets, or manipulate availability status by forging lease heartbeats.
Affected Systems
The vulnerability affects the Open Cluster Management platform used to orchestrate Kubernetes clusters. All deployments of open-cluster-management that expose a gRPC broker and support the ce-clustername header are potentially impacted. Specific version information is not disclosed.
Risk and Exploitability
The CVSS score of 3.3 indicates low overall severity, and no EPSS score is available, meaning the exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based, requiring an attacker to send crafted gRPC messages to the broker from a registered cluster. Successful exploitation can give the cluster control over other clusters’ resources within the same hub, but no remote code execution or full system compromise is described.
OpenCVE Enrichment