Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25655

Опубликовано: 22 окт. 2020
Источник: redhat
CVSS3: 5.7
EPSS Низкий

Описание

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.

A flaw was found in the ManagedClusterView API, allowed secrets to be disclosed to users without the correct permissions. Views created for an admin user are made available for a short time to users with view-only permission. In this short time window, the user with view-only permission can read cluster secrets that should only be disclosed to admin users. The highest threat from this vulnerability is to confidentiality.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1888475open-cluster-management: RBAC bypass may disclose cluster secrets to other users

EPSS

Процентиль: 44%
0.00212
Низкий

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
около 5 лет назад

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.

github
больше 3 лет назад

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.

EPSS

Процентиль: 44%
0.00212
Низкий

5.7 Medium

CVSS3