Product
high
advisory
Information Disclosure Vulnerability in IBM Instana Agent Operator
1 TTP 1 CVEIBM Instana Agent Operator versions 1.0.303 through 1.0.323 contain a vulnerability involving missing namespace validation that allows an authenticated attacker to copy sensitive etcd mTLS credentials to an attacker-controlled namespace.
Observability with Instana +1
vulnerability
kubernetes
openshift
credential-access
1t
1c
critical
advisory
IBM Instana Agent Operator RBAC Hijacking Vulnerability
1 TTP 1 CVEAn authenticated tenant can perform privilege escalation in Kubernetes clusters using IBM Instana Agent Operator (Build 1.0.303 through 1.0.323) by creating a malicious Custom Resource that overwrites shared cluster-level RBAC objects.
Instana Agent +1
privilege-escalation
kubernetes
cloud
1t
1c