Privilege Escalation in Open Cluster Management by Malicious User Access
CVE-2023-2250
6.7MEDIUM
What is CVE-2023-2250?
A security flaw in Open Cluster Management (OCM) allows users with access to worker nodes containing the cluster-manager-registration-controller or cluster-manager deployments to exploit the system. A malicious actor can leverage this vulnerability to bind the cluster-admin role to any service account, enabling unauthorized access to list all secrets across all Kubernetes namespaces. This could lead to severe implications for cluster security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MCE 2.3.0