Описание
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
A flaw was found in the cluster-backup-operator. A privileged user with administrative access to a specific namespace could exploit a vulnerability in the backup restoration process. This flaw allows them to redirect sensitive information, such as cloud provider credentials and access tokens, from backup operations into other namespaces, including those they control. This could lead to unauthorized access to critical system resources and the disclosure of confidential data.
Отчет
This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. A namespace administrator within the open-cluster-management-backup namespace can exploit the cluster-backup-operator to redirect sensitive credential Secrets and ConfigMaps from backed-up namespaces into any target namespace, including those controlled by the attacker. This allows for a cross-namespace write of credential material, potentially leading to unauthorized access to cloud provider credentials, pull secrets, and ManagedServiceAccount tokens.
Меры по смягчению последствий
To mitigate this issue, restrict administrative access to the open-cluster-management-backup namespace. Only trusted administrators should have permissions to create or modify Restore Custom Resources within this namespace, as this action is required to exploit the vulnerability.
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
Windows Key Guard Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
EPSS
7.1 High
CVSS3