Описание
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.
A flaw was found in the Cluster API Provider Metal3 IP Address Manager (IPAM) controller. The controller's ClusterRole granted excessive permissions, allowing full create, read, update, and delete (CRUD) access to core/v1 Secrets. If the controller pod were compromised, an attacker could leverage these permissions to read, modify, or delete sensitive data within the namespace. This could lead to the exposure of credentials and other sensitive information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Engine for Kubernetes | multicluster-engine/capoa-bootstrap-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-cluster-api-controllers-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-machine-controllers | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-machine-controllers-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-capi-rhel9-operator | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-machine-api-operator | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.4 Medium
CVSS3
Связанные уязвимости
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.
IPAM controller service account granted unnecessary full access to Secrets
6.4 Medium
CVSS3