Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp26-rmxw-4cpv

Опубликовано: 12 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the ocm-managed-cluster annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the ocm-managed-cluster annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

EPSS

Процентиль: 22%
0.00298
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-441

Связанные уязвимости

CVSS3: 9.9
redhat
около 1 месяца назад

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

CVSS3: 9.9
nvd
около 1 месяца назад

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

EPSS

Процентиль: 22%
0.00298
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-441