What happened
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
Affected versions
RHODF-4.16-RHEL-9: before 0.14.9 (semver); 0.15.0 through before 0.15.5 (semver); 0.16.0 through before 0.16.7 (semver); 0.17.0 through before 0.17.2 (custom); 0.18.0-m0 through before 0.18.0-rc0 (custom) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.