REDHAT-BUG-2514228: High severity Red Hat Red Hat Advanced Cluster Management (RHACM) vulnerability
A flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM). The GitOpsCluster controller uses the tenant-controlled spec.argoServer.argoNamespace field to determine where spoke cluster bearer token Secrets are written. The controller copies ManagedServiceAccount tokens from privileged managed-cluster hub namespaces into the attacker-specified namespace. The only guard (VerifyArgocdNamespace) is bypassed by a tenant-settable annotation on the same CR. A tenant can exfiltrate spoke bearer tokens and bypass ArgoCD AppProject constraints.
Upstream repo: https://github.com/stolostron/multicloud-integrations Audited commit: d88a168 Jira tracker: ACM-38644
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2514228?
The severity of REDHAT-BUG-2514228 is categorized as high with a score of 7.
How do I fix REDHAT-BUG-2514228?
To fix REDHAT-BUG-2514228, ensure that proper validation is implemented for the tenant-controlled spec.argoServer.argoNamespace field in the GitOpsCluster controller.
What is the description of REDHAT-BUG-2514228?
REDHAT-BUG-2514228 describes a flaw in the multicloud-integrations component of Red Hat Advanced Cluster Management, affecting how bearer token Secrets are managed.
Which component is affected by REDHAT-BUG-2514228?
The affected component in REDHAT-BUG-2514228 is the multicloud-integrations of Red Hat Advanced Cluster Management (RHACM).
When was REDHAT-BUG-2514228 published?
REDHAT-BUG-2514228 was published on August 11, 2026.