Skip to content

Cluster-level Privilege Escalation

Moderate
beeme1mr published GHSA-cwf6-xj49-wp83 Apr 12, 2023

Package

OpenFeature Operator (Kubernetes)

Affected versions

< 0.2.32

Patched versions

0.2.32

Description

Impact

On a node controlled by an attacker or malicious user, the lax permissions configured on open-feature-operator-controller-manager can be used to further escalate the privileges of any service account in the cluster.

The increased privileges could be used to modify cluster state, leading to DoS, or read sensitive data, including secrets.

Patches

The patch mitigates this issue by restricting the resources the open-feature-operator-controller-manager can modify.

Severity

Moderate

CVE ID

CVE-2023-29018

Weaknesses

No CWEs

Credits