Submariner Operator sets unnecessary RBAC permissions in helm charts
Moderate severity
GitHub Reviewed
Published
May 17, 2024
to the GitHub Advisory Database
•
Updated Jul 17, 2024
Package
Affected versions
< 0.16.4
>= 0.17.0, <= 0.18.0-m3
Patched versions
0.16.4
Description
Published by the National Vulnerability Database
May 17, 2024
Published to the GitHub Advisory Database
May 17, 2024
Reviewed
May 17, 2024
Last updated
Jul 17, 2024
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
References