PT-2020-16150 · Kubernetes · Managedclusterview Api

Published

2020-11-09

·

Updated

2020-11-18

·

CVE-2020-25655

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ManagedClusterView API (affected versions not specified)
Description An issue in the ManagedClusterView API could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission, allowing them to read cluster secrets that should only be disclosed to admin users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25655

Affected Products

Managedclusterview Api