OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalation
High severity
GitHub Reviewed
Published
Dec 31, 2024
to the GitHub Advisory Database
•
Updated Jan 2, 2025
Description
Published by the National Vulnerability Database
Dec 31, 2024
Published to the GitHub Advisory Database
Dec 31, 2024
Reviewed
Jan 2, 2025
Last updated
Jan 2, 2025
A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.
References