Impact
The flaw in multicluster-observability-addon allows an attacker to reach a debug endpoint without authentication because the addon‑framework library is misconfigured. Accessing this endpoint exposes operational details such as goroutine listings, heap snapshots, and command-line arguments, which can aid further reconnaissance. The vulnerability does not provide a path to remote code execution.
Affected Systems
This issue affects Red Hat Advanced Cluster Management for Kubernetes 2. No specific sub‑version is listed, so all versions of product 2 are potentially impacted.
Risk and Exploitability
At a CVSS score of 5.4, the vulnerability presents moderate risk, and the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation, with no listing in the CISA KEV catalog. The public documentation shows that the addon provides a debug interface that can be accessed without authentication; while the exact ports are not explicitly documented, the recommended network policy targets ports 6060 and 8443, suggesting that these are the listening endpoints. Therefore, an attacker would need to reach the affected pods over the cluster network, targeting those ports if present, to trigger the information disclosure. The scope is limited to the pods within the cluster, and no remote code execution is possible.
OpenCVE Enrichment