piraeus-operator allows attacker to impersonate service account
High severity
GitHub Reviewed
Published
May 3, 2024
to the GitHub Advisory Database
•
Updated Jul 3, 2024
Package
Affected versions
<= 2.5.0
Patched versions
None
Description
Published by the National Vulnerability Database
May 3, 2024
Published to the GitHub Advisory Database
May 3, 2024
Reviewed
May 3, 2024
Last updated
Jul 3, 2024
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
References