An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.