Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4gv-pjmh-c735

Опубликовано: 07 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

Пакеты

Наименование

open-cluster-management.io/ocm

go
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 2%
0.00112
Низкий

8.2 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.2
redhat
4 месяца назад

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

CVSS3: 8.2
nvd
4 месяца назад

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

EPSS

Процентиль: 2%
0.00112
Низкий

8.2 High

CVSS3

Дефекты

CWE-295