Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58fx-7v9q-3g56

Опубликовано: 28 янв. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

OpenShift GitOps Operator Namespace Isolation Break

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

Пакеты

Наименование

github.com/redhat-developer/gitops-operator

go
Затронутые версииВерсия исправления

< 1.16.2

1.16.2

EPSS

Процентиль: 18%
0.00058
Низкий

8.2 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 8.2
redhat
около 1 года назад

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

CVSS3: 8.2
nvd
около 1 года назад

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

suse-cvrf
12 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 18%
0.00058
Низкий

8.2 High

CVSS3

Дефекты

CWE-668