An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.
2022-02-18T18:15:09.833
2024-11-21T06:23:13.213
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | konveyor | mig-controller | < 1.5.2 | Yes |
Application | konveyor | mig-controller | < 1.6.3 | Yes |
Application | redhat | migration_toolkit | 1.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | No |
Operating System | redhat | enterprise_linux | 8.0 | No |
Application | redhat | migration_toolkit | 1.5 | Yes |
Application | redhat | migration_toolkit | 1.6 | Yes |