Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40325
HistoryApr 28, 2023 - 2:55 a.m.

Privilege Escalation

2023-04-2802:55:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
github
vulnerability
worker nodes
cluster-manager
service account
kubernetes namespaces
privilege escalation

EPSS

0

Percentile

9.0%

github.com/open-cluster-management-io/registration-operator is vulnerable to Privilege Escalation. The vulnerability exists when a user has access to the worker nodes with the cluster-manager-registration-controller or cluster-manager deployments which allows a malicious user to bind the cluster-admin to any service account or use the service account to list all secrets for all Kubernetes namespaces, leading into a cluster-level privilege escalation.

EPSS

0

Percentile

9.0%

Related for VERACODE:40325