Описание
When deploying only the Topic Operator or only the User Operator via the Kafka custom resource, the Entity Operator's ServiceAccount retains RBAC rights for both operators rather than scoping permissions to the one actually deployed. This allows the ServiceAccount to access KafkaUser custom resources and Secrets even when the User Operator is not deployed, or access KafkaTopic custom resources when the Topic Operator is not deployed, violating the principle of least privilege. There is no workaround for this issue. Fixed in Strimzi 1.0.1 and 1.1.0.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| streams for Apache Kafka 2 | cluster-operator | Fix deferred | ||
| streams for Apache Kafka 3 | cluster-operator | Fix deferred |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-272
https://bugzilla.redhat.com/show_bug.cgi?id=2490660strimzi-cluster-operator: Unrestricted access to all Secrets within namespace watched by the Topic operator in Strimzi
5.4 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.4
github
около 2 месяцев назад
Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
5.4 Medium
CVSS3