Impact
A flaw in the LogRule::matches function causes the evaluation to halt at the first wildcard pattern within a rule, preventing subsequent deny entries from being processed. As a result, an attacker can bypass log access controls and read logs from other workloads that should be restricted, compromising confidentiality.
Affected Systems
The vulnerability affects Eclipse Ankaios versions 0.6.0 up to, but not including, 1.0.4. The product is maintained by the Eclipse Foundation.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog. While the exact attack vector is not explicitly documented, it is inferred that exploitation requires access to the agent control‑interface and possibly elevation of privilege within the same environment. The vulnerability is therefore likely exploitable in an internal or local context rather than over the public network.
OpenCVE Enrichment