Описание
The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on open-feature-operator-controller-manager to escalate the privileges of any SA in the cluster. The increased privileges could be used to modify cluster state, leading to DoS, or read sensitive data, including secrets. Version 0.2.32 mitigates this issue by restricting the resources the open-feature-operator-controller-manager can modify.
Ссылки
- Release Notes
- Vendor Advisory
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.2.32 (исключая)
cpe:2.3:a:linuxfoundation:openfeature:*:*:*:*:*:kubernetes:*:*
EPSS
Процентиль: 50%
0.00274
Низкий
8 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-269
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.8
github
почти 3 года назад
OpenFeature Operator vulnerable to Cluster-level Privilege Escalation
EPSS
Процентиль: 50%
0.00274
Низкий
8 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-269
NVD-CWE-noinfo