OpenFeature Operator vulnerable to Cluster-level Privilege Escalation
CVE-2023-29018
8.1HIGH
What is CVE-2023-29018?
The OpenFeature Operator has a security vulnerability that allows an attacker to exploit misconfigured permissions on the open-feature-operator-controller-manager. In the presence of an existing arbitrary code execution vulnerability, an attacker can escalate privileges of any Service Account (SA) within the Kubernetes cluster. This could result in unauthorized modifications to cluster resources, leading to service disruptions or unauthorized access to sensitive data, including secrets. To mitigate this issue, version 0.2.32 has been released, which implements stricter resource modification controls on the operator.
Affected Version(s)
open-feature-operator < 0.2.32
