CVE-2020-25655
09.11.2020, 15:15
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | 2.0 |
𝑥
= Vulnerable software versions