Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78234

Опубликовано: 08 сент. 2026
Источник: redhat
CVSS3: 9.9

Описание

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.

Отчет

Red Hat has determined that this vulnerability is Important severity and not Critical because authentication is required. The hawtio-operator directly reads the cluster Service CA private key and issues certificates with an attacker-controlled Common Name, effectively providing a signing oracle to any namespace editor. Exploitation enables cross-tenant service impersonation and, via Jolokia MBean invocation on Java workloads, remote code execution. Red Hat recommends that the operator stop reading the Service CA signing key and instead use the Kubernetes CSR API with a dedicated signer or a Hawtio-private CA.

Меры по смягчению последствий

Do not set spec.routeHostName to values outside the operator's own namespace service names. Restrict which users can create or modify Hawtio custom resources via RBAC. Audit existing Hawtio CR instances for unexpected routeHostName values and rotate any TLS certificates that may have been issued with incorrect Common Names.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4rhbac-4/hawtio-operator-bundleAffected
Red Hat build of Apache Camel - HawtIO 4rhbac-4/hawtio-rhel9Affected
rhbac-4/hawtio-operator-bundleFixedRHSA-2026:6612009.09.2026
rhbac-4/hawtio-rhel9-operatorFixedRHSA-2026:6612009.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2524894hawtio-operator: hawtio-operator: Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
9 дней назад

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.

CVSS3: 9.9
github
9 дней назад

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.

9.9 Critical

CVSS3