Back to search
CVE-2023-3027
Published: Jun 5, 2023
Modified: Jan 8, 2025
PUBLISHED
Description
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.
| Vendor | Product | Versions |
|---|---|---|
n/a | RHACM | affected 2.5, 2.6, 2.7 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now