Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3027


The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.


Published

2023-06-05T22:15:12.293

Last Modified

2025-01-08T17:15:13.653

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-269
  • Type: Secondary
    CWE-269
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat advanced_cluster_management_for_kubernetes 2.5 Yes
Application redhat advanced_cluster_management_for_kubernetes 2.6 Yes
Application redhat advanced_cluster_management_for_kubernetes 2.7 Yes

References