漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege
Vulnerability Description
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount token would grant an attacker read access to all Secrets across the hub cluster, including managed-cluster kubeconfigs and other sensitive credentials.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
Red Hat Insights Client 权限许可和访问控制问题漏洞
Vulnerability Description
Red Hat Insights Client是美国Red Hat公司的一款系统监控与支撑客户端。 Red Hat Insights Client存在权限许可和访问控制问题漏洞,该漏洞源于insights-client组件的ServiceAccount绑定到授予集群范围secrets读取权限的ClusterRole,导致权限过大,可能导致攻击者读取集群中所有Secrets,包括敏感凭据。
CVSS Information
N/A
Vulnerability Type
N/A