Описание
A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
Отчет
Red Hat rates this vulnerability as Important instead of Critical. While full cluster compromise is possible, it requires the attacker to already possess authenticated namespace administrator credentials, reducing the attack surface to authorized internal users rather than external attackers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-operator-bundle | Not affected | ||
| Red Hat OpenShift GitOps 1.16 | openshift-gitops-1/gitops-rhel8-operator | Fixed | RHSA-2025:23207 | 15.12.2025 |
| Red Hat OpenShift GitOps 1.17 | openshift-gitops-1/gitops-rhel8-operator | Fixed | RHSA-2025:23206 | 15.12.2025 |
| Red Hat OpenShift GitOps 1.18 | openshift-gitops-1/gitops-rhel8-operator | Fixed | RHSA-2025:23203 | 15.12.2025 |
| Red Hat OpenShift GitOps 1.18 | openshift-gitops-1/gitops-rhel8-operator | Fixed | RHSA-2026:1017 | 22.01.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
9.1 Critical
CVSS3
Связанные уязвимости
A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources
9.1 Critical
CVSS3