CyberRota Analysis
AI-GeneratedA critical vulnerability exists in Lighthouse that allows remote attackers to exploit compromised spoke clusters by manipulating labels or annotations on broker objects. This enables unauthorized injection of EndpointSlices and ServiceImports into any namespace, including sensitive system namespaces like kube-system, potentially leading to privilege escalation and severe system compromise. Organizations using Lighthouse should prioritize immediate remediation to protect their clusters from potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.