Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users
Vulnerability Description
ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, but can read `InfraEnv` objects and recover the referenced Secret's `.dockerconfigjson` data from status. This bypasses the Kubernetes/OpenShift RBAC separation between read-only namespace viewers and Secret readers. In the reproduced proof, the same ServiceAccount was denied `get` and `list` on Secrets, but recovered synthetic pull-secret `username`, `password`, `email`, and base64 `auth` fields through `InfraEnv.status`.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Vulnerability Type
通过发送数据的信息暴露
Vulnerability Title
Red Hat assisted-service 安全漏洞
Vulnerability Description
Red Hat assisted-service是美国红帽(Red Hat)公司的一个提供 REST API 的后端服务组件,主要服务于OpenShift生态系统。 Red Hat assisted-service存在安全漏洞,该漏洞源于在拉取密钥验证失败时将原始拉取密钥内容写入InfraEnv状态消息中,可能导致绕过RBAC分离并恢复密钥数据。
CVSS Information
N/A
Vulnerability Type
N/A