PT-2026-50541 · Maven · Io.Strimzi:Strimzi
Publicado
2026-06-17
·
Atualizado
2026-06-18
·
CVE-2026-55226
CVSS v3.1
5.4
Média
| Vetor | AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |
Impact
When only the Topic or only the User operators are deployed as part of the Entity Operator in the
Kafka custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access KafkaUser custom resources and Secrets when the User operator is not deployed and access KafkaTopic custom resources when the Topic operator is not deployed.Patches
The issue is fixed in Strimzi 1.0.1 and 1.1.0.
Workarounds
There is no workaround for this issue.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Io.Strimzi:Strimzi