Product
Authorization Flaw in Red Hat Multicluster Engine Clusterclaims-controller
1 TTP 1 CVEA vulnerability in the Red Hat multicluster engine (MCE) allows authenticated tenants to delete unauthorized ManagedCluster resources due to a missing ownership check in the clusterclaims-controller.
Privilege Escalation in Red Hat Advanced Cluster Management
2 TTPs 2 CVEsAn insecure configuration in the Red Hat Advanced Cluster Management Application Subscription controller allows users with namespace-scoped edit privileges to escalate to cluster-admin by deploying unauthorized cluster-scoped resources via Helm charts.
Red Hat Advanced Cluster Management Vulnerability Allows Cluster-Admin Privilege Escalation
1 TTP 1 CVEA flaw exists in the cluster-proxy service-proxy component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE), allowing an authenticated hub principal to inject an Impersonate-Group header into proxied requests, bypassing validation, and leveraging the spoke ServiceAccount's unrestricted impersonation permissions to escalate privileges to cluster-admin on all managed clusters.