See how red hat advanced cluster management compares to other vendors in security performance
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). The HelmRelease controller's NewManager() function builds Helm action.Configuration using the controller's own kubeconfig without impersonation or SubjectAccessReview. No GVK filter or namespace coercion is applied, allowing cluster-scoped or cross-namespace Helm chart templates to be applied with the controller's wildcard (//) ServiceAccount privileges. A tenant who can create a HelmRelease CR can achieve arbitrary resource deployment cluster-wide.
Upstream repo: https://github.com/stolostron/multicloud-operators-subscription Audited commit: 48ae4defaa5b719e0664e1de7413c96029c938bc Jira tracker: ACM-38623