CVE-2023-3027
published 2023-06-05CVE-2023-3027: The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.9th percentile
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | — | — |
| redhat | advanced_cluster_management_for_kubernetes | — | — |
| redhat | advanced_cluster_management_for_kubernetes | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffmc-4rrr-xm85: The grc-policy-propagator allows security escalation within the cluster
ghsa_unreviewed·2023-06-06
CVE-2023-3027 [HIGH] CWE-269 GHSA-ffmc-4rrr-xm85: The grc-policy-propagator allows security escalation within the cluster
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.
Red Hat
ACM: governance policy propagator privilege escalation
vendor_redhat·2023-05-31·CVSS 7.8
CVE-2023-3027 [HIGH] CWE-269 ACM: governance policy propagator privilege escalation
ACM: governance policy propagator privilege escalation
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.
Package: governance-policy-propagator (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-05
Published