Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://gist.github.com/HouqiyuA/27879a6366a65fcd5f6c6fcbcf68d8e3 | third party advisory |