Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

redhat логотип

CVE-2026-55226

около 2 месяцев назад

When deploying only the Topic Operator or only the User Operator via the Kafka custom resource, the Entity Operator's ServiceAccount retains RBAC rights for both operators rather than scoping permissions to the one actually deployed. This allows the ServiceAccount to access KafkaUser custom resources and Secrets even when the User Operator is not deployed, or access KafkaTopic custom resources when the Topic Operator is not deployed, violating the principle of least privilege. There is no workaround for this issue. Fixed in Strimzi 1.0.1 and 1.1.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-r427-j2h7-wv3m

около 2 месяцев назад

Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-55226

When deploying only the Topic Operator or only the User Operator via the Kafka custom resource, the Entity Operator's ServiceAccount retains RBAC rights for both operators rather than scoping permissions to the one actually deployed. This allows the ServiceAccount to access KafkaUser custom resources and Secrets even when the User Operator is not deployed, or access KafkaTopic custom resources when the Topic Operator is not deployed, violating the principle of least privilege. There is no workaround for this issue. Fixed in Strimzi 1.0.1 and 1.1.0.

CVSS3: 5.4
около 2 месяцев назад
github логотип
GHSA-r427-j2h7-wv3m

Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator

CVSS3: 5.4
около 2 месяцев назад

Уязвимостей на страницу