CVE Database
/

CVE-2023-3027

Back to search

CVE-2023-3027

Published: Jun 5, 2023

Modified: Jan 8, 2025

PUBLISHED

Description

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.

VendorProductVersions

n/a

RHACM

affected
2.5, 2.6, 2.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now