Permissions, Privileges, and Access Controls in Service Interconnect - CVE-2023-5056
Published: November 8, 2023
Service Interconnect
Detailed vulnerability description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due improperly imposed security restrictions in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated user in the adjacent cluster to view deployments in all namespaces in the cluster.