Submariner Operator sets unnecessary RBAC permissions
Moderate severity
GitHub Reviewed
Published
May 17, 2024
to the GitHub Advisory Database
•
Updated Jan 21, 2025
Package
Affected versions
>= 0.16.0-m0, < 0.16.4
>= 0.17.0-m0, < 0.17.2
< 0.15.4
>= 0.18.0-m0, < 0.18.0-rc0
Patched versions
0.16.4
0.17.2
0.15.4
0.18.0-rc0
Description
Published by the National Vulnerability Database
May 17, 2024
Published to the GitHub Advisory Database
May 17, 2024
Reviewed
May 17, 2024
Last updated
Jan 21, 2025
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
References