REDHAT-BUG-2512150: High severity Stolostron search-v2-operator vulnerability
A single hub-side Search CR field (Collector.ImageOverride) selects the container image deployed to all managed clusters via addon-framework ManifestWork. The spoke pod runs under a ClusterRole granting / get/list/watch (FIND-006), so this is fleet-wide secret-read RCE. The addon.go:55 default comes from env COLLECTORIMAGE, and the package-global is mutated without restart on first reconcile only. A hub admin or any principal with patch access to the Search CR can replace the collector image across the entire fleet.
Upstream: stolostron/search-v2-operator
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2512150?
The severity of REDHAT-BUG-2512150 is high, rated at 7.
What is the risk associated with REDHAT-BUG-2512150?
The risk associated with REDHAT-BUG-2512150 is rated at 33.
How does REDHAT-BUG-2512150 allow for remote code execution?
REDHAT-BUG-2512150 allows for remote code execution through fleet-wide secret-read access due to the improper permissions of a spoke pod.
What component is affected by REDHAT-BUG-2512150?
The component affected by REDHAT-BUG-2512150 is the Stolostron search-v2-operator.
What is the potential impact of exploiting REDHAT-BUG-2512150?
Exploiting REDHAT-BUG-2512150 can lead to unauthorized access and manipulation of container images across all managed clusters.