Описание
When the Strimzi cluster operator is deployed with watchAnyNamespace=true (or a multi-namespace list), any namespace editor can set Kafka.spec.entityOperator.userOperator.watchedNamespace (or topicOperator.watchedNamespace) to an arbitrary namespace. The cluster operator then creates a Role granting full CRUD on Secrets in the target namespace and a RoleBinding pointing to a ServiceAccount in the attacker's namespace — effectively granting cluster-admin-equivalent access via kube-system secret exfiltration. The RBAC objects created cross-namespace have their ownerReferences deliberately stripped, making the privilege grant persistent even after the Kafka CR or attacker namespace is deleted. Fixed in Strimzi 1.0.1 and 1.1.0 by adding a dedicated environment variable to explicitly enable the watched namespace feature (disabled by default).
Меры по смягчению последствий
For users who cannot upgrade immediately, deploy a Kubernetes admission policy agent (such as Kyverno or OPA Gatekeeper) to block or restrict the use of the watchedNamespace field in Kafka custom resources (Kafka.spec.entityOperator.userOperator.watchedNamespace and Kafka.spec.entityOperator.topicOperator.watchedNamespace). Additionally, audit existing Kafka custom resources for unexpected watchedNamespace configurations and review RoleBindings in sensitive namespaces.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| streams for Apache Kafka 2 | cluster-operator | Affected | ||
| streams for Apache Kafka 3 | cluster-operator | Affected |
Показывать по
Дополнительная информация
Статус:
8 High
CVSS3
Связанные уязвимости
Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
8 High
CVSS3