Skip to content

piraeus-operator allows attacker to impersonate service account

Moderate severity GitHub Reviewed Published May 3, 2024 to the GitHub Advisory Database • Updated May 3, 2024

Package

gomod github.com/piraeusdatastore/piraeus-operator/v2 (Go)

Affected versions

<= 2.5.0

Patched versions

None

Description

There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.

References

Published by the National Vulnerability Database May 3, 2024
Published to the GitHub Advisory Database May 3, 2024
Reviewed May 3, 2024
Last updated May 3, 2024

Severity

Moderate

Weaknesses

No CWEs

CVE ID

CVE-2024-33398

GHSA ID

GHSA-6fg2-hvj9-832f
Checking history
See something to contribute? Suggest improvements for this vulnerability.