漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users
Vulnerability Description
ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, but can read `InfraEnv` objects and recover the referenced Secret's `.dockerconfigjson` data from status. This bypasses the Kubernetes/OpenShift RBAC separation between read-only namespace viewers and Secret readers. In the reproduced proof, the same ServiceAccount was denied `get` and `list` on Secrets, but recovered synthetic pull-secret `username`, `password`, `email`, and base64 `auth` fields through `InfraEnv.status`.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Vulnerability Type
通过发送数据的信息暴露
Vulnerability Title
Red Hat assisted-service 安全漏洞
Vulnerability Description
Red Hat assisted-service是美国红帽(Red Hat)公司的一个提供 REST API 的后端服务组件,主要服务于OpenShift生态系统。 Red Hat assisted-service存在安全漏洞,该漏洞源于在拉取密钥验证失败时将原始拉取密钥内容写入InfraEnv状态消息中,可能导致绕过RBAC分离并恢复密钥数据。
CVSS Information
N/A
Vulnerability Type
N/A