Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-13888

Опубликовано: 15 дек. 2025
Источник: redhat
CVSS3: 9.1

Описание

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.

Отчет

Red Hat rates this vulnerability as Important instead of Critical. While full cluster compromise is possible, it requires the attacker to already possess authenticated namespace administrator credentials, reducing the attack surface to authorized internal users rather than external attackers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-operator-bundleNot affected
Red Hat OpenShift GitOps 1.16openshift-gitops-1/gitops-rhel8-operatorFixedRHSA-2025:2320715.12.2025
Red Hat OpenShift GitOps 1.17openshift-gitops-1/gitops-rhel8-operatorFixedRHSA-2025:2320615.12.2025
Red Hat OpenShift GitOps 1.18openshift-gitops-1/gitops-rhel8-operatorFixedRHSA-2025:2320315.12.2025
Red Hat OpenShift GitOps 1.18openshift-gitops-1/gitops-rhel8-operatorFixedRHSA-2026:101722.01.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2418361openshift-gitops-operator: OpenShift GitOps: Namespace Admin Cluster Takeover via Privileged Jobs

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
9 месяцев назад

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.

CVSS3: 9.1
github
9 месяцев назад

OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources

9.1 Critical

CVSS3