Описание
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources.
Отчет
This vulnerability is rated as Important. A namespace administrator within the open-cluster-management-backup namespace in Red Hat Advanced Cluster Management for Kubernetes can initiate a cluster-wide denial of service. This occurs by leveraging the cleanupBeforeRestore: CleanupAll option in a Restore Custom Resource, which causes the cluster-backup-operator to delete all ACM/Hive-labelled Secrets and ConfigMaps across the hub cluster, regardless of their restore labels.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
EPSS
7.1 High
CVSS3