Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xp42-v53j-r9gh

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

EPSS

Процентиль: 6%
0.0016
Низкий

7.1 High

CVSS3

Дефекты

CWE-441

Связанные уязвимости

CVSS3: 7.1
redhat
8 дней назад

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

CVSS3: 7.1
nvd
6 дней назад

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

EPSS

Процентиль: 6%
0.0016
Низкий

7.1 High

CVSS3

Дефекты

CWE-441