PT-2020-16150 · Kubernetes · Managedclusterview Api
Published
2020-11-09
·
Updated
2020-11-18
·
CVE-2020-25655
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManagedClusterView API (affected versions not specified)
Description
An issue in the ManagedClusterView API could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission, allowing them to read cluster secrets that should only be disclosed to admin users.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Managedclusterview Api