Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5056

Опубликовано: 26 окт. 2023
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2239517skupper-operator: privelege escalation via config map

EPSS

Процентиль: 20%
0.00273
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
больше 2 лет назад

A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.

CVSS3: 6.8
fstec
почти 3 года назад

Уязвимость пакета Skupper программного средства Red Hat Service Interconnect, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 20%
0.00273
Низкий

6.8 Medium

CVSS3

Уязвимость CVE-2023-5056