Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g9w9-rqjq-9rf5

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.

EPSS

Процентиль: 13%
0.00223
Низкий

7.7 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.7
redhat
около 1 месяца назад

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.

CVSS3: 7.7
nvd
около 1 месяца назад

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.

EPSS

Процентиль: 13%
0.00223
Низкий

7.7 High

CVSS3

Дефекты

CWE-862