Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://gist.github.com/HouqiyuA/f972d1c152f3b8127af01206f7c2af0d | third party advisory |