REDHAT-BUG-2514220: High severity multicluster engine (MCE) vulnerability
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). When a ClusterCurator resource is created with metadata.name different from metadata.namespace, the ApplyRBACHypershift function creates a RoleBinding in an arbitrary namespace (specified by curator.Name) and a cluster-scoped ClusterRoleBinding (curator-crb), both binding the tenant's namespace-local cluster-installer ServiceAccount to the curator ClusterRole. This ClusterRole grants cluster-wide secrets:get/create, managedclusteractions:, and hostedclusters/nodepools/managedclusters delete permissions. A tenant can escalate from namespace-local access to cluster-wide privileges with no admission controls.
Upstream repo: https://github.com/stolostron/cluster-curator-controller Audited commit: 0e050d6e5edf5d2fbc2794fa468bdffd056b444f Jira tracker: ACM-38729
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2514220?
The severity of REDHAT-BUG-2514220 is classified as high with a risk score of 7.
What component is affected by REDHAT-BUG-2514220?
The flaw is found in the cluster-curator-controller component of the multicluster engine (MCE).
How do I fix REDHAT-BUG-2514220?
To fix REDHAT-BUG-2514220, ensure that the ClusterCurator resource is created with metadata.name matching metadata.namespace.
What is the potential impact of REDHAT-BUG-2514220?
The potential impact of REDHAT-BUG-2514220 includes the creation of a RoleBinding in an arbitrary namespace, which can lead to unauthorized access.
What versions are affected by REDHAT-BUG-2514220?
Specific versions of the multicluster engine (MCE) that utilize the cluster-curator-controller component are impacted, and details can be reviewed in the vulnerability report.