Back

HIGH

openshift: Users with permission to schedule pods on master nodes can access credentials for AWS IAM roles

Published Mar 19, 2021

Description

A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing management access to AWS resources. With access to the security credentials, the user then has access to the entire infrastructure. Impact to data and system availability is high.

Affected products

Remediation

Red Hat mitigation

Do not run untrusted workloads with `hostnetwork` access on master nodes. If additional workloads are run on master hosts, use caution when providing access to hostnetwork. A workload that runs hostnetwork on a master host is effectively root on the cluster and must be trusted accordingly. https://docs.openshift.com/container-platform/4.4/authentication/managing-security-context-constraints.html

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 19, 2021
Updated Aug 4, 2024
Reserved Mar 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 12, 2019
ENISA EUVD
Assigner redhat
Published Mar 19, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-2220