A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2024-25133 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2260372 | issue tracking |
https://github.com/openshift/hive/pull/2306 |