Hwameistor Potential Permission Leakage of Cluster Level
Moderate severity
GitHub Reviewed
Published
Aug 28, 2024
in
hwameistor/hwameistor
•
Updated Nov 18, 2024
Description
Published by the National Vulnerability Database
Aug 28, 2024
Published to the GitHub Advisory Database
Aug 29, 2024
Reviewed
Aug 29, 2024
Last updated
Nov 18, 2024
Impact
What kind of vulnerability is it? Who is impacted?
This ClusterRole has * verbs of * resources. If a malicious user can access the worker node which has hwameistor's deployment, he/she can abuse these excessive permissions to do whatever he/she likes to the whole cluster, resulting in a cluster-level privilege escalation.
Patches
Has the problem been patched? What versions should users upgrade to?
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
Update and Limit the ClusterRole using security-role.
References
Are there any links users can visit to find out more?
issues:
hwameistor/hwameistor#1457
hwameistor/hwameistor#1460
also reported by users via mails:
sparkEchooo, younaman
References