A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Multicluster engine for Kubernetes 2.1 | RedHat | multicluster-engine/cluster-curator-controller-rhel9:1787201612 | * |
| Multicluster engine for Kubernetes 2.11 | RedHat | multicluster-engine/cluster-curator-controller-rhel9:1787238383 | * |
| Multicluster engine for Kubernetes 2.6 | RedHat | multicluster-engine/cluster-curator-controller-rhel9:1787264185 | * |
| Multicluster engine for Kubernetes 2.8 | RedHat | multicluster-engine/cluster-curator-controller-rhel9:1787259011 | * |
| Multicluster engine for Kubernetes 2.9 | RedHat | multicluster-engine/cluster-curator-controller-rhel9:1787201646 | * |