Impact
The insights‑operator‑gather ClusterRole improperly grants its service account read access to all secrets in the core API group without any namespace or resource restriction. By creating a pod that uses this service account, an attacker can read the contents of any secret in any namespace, potentially exposing credentials, certificates, or other sensitive data. The weakness is a privilege management flaw (CWE‑269).
Affected Systems
Red Hat OpenShift Container Platform 4 is affected because the vulnerability resides in the insights‑operator ClusterRole bundled with this product. No specific patch release versions are listed, so the issue likely applies to all current 4.x releases until a fix is provided.
Risk and Exploitability
The CVSS score is 7.7, indicating a high severity impact. EPSS is not available, so the exploitation probability is unknown; however, the vulnerability is not currently listed in CISA KEV. The likely attack vector is via the ability to run a pod using the gather service account. If an attacker can create pods or has privileges to bind the service account to a pod, they can exploit this misconfiguration to read cluster‑wide secrets.
OpenCVE Enrichment