CyberRota Analysis
AI-GeneratedA critical vulnerability exists in the search-v2-operator, which has been granted ClusterRole permissions equivalent to a cluster administrator. This excessive privilege allows the operator to impersonate other entities, modify Role-Based Access Control (RBAC) settings, approve Certificate Signing Requests (CSRs), and manage ManifestWork, potentially enabling privilege escalation within the cluster. Organizations utilizing this operator should prioritize immediate remediation to mitigate the risk of unauthorized access and control over their Kubernetes environments.
Original NVD Description
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.