CyberRota Analysis
AI-GeneratedA vulnerability in the multicluster-observability-addon allows a managed-cluster identity to access configuration resources beyond its designated namespace, potentially exposing sensitive hub Secrets to unauthorized access. Organizations utilizing this addon should prioritize remediation efforts due to the high severity of the issue, which could lead to significant data breaches. Immediate action is recommended for those managing multi-cluster environments to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.