Back

HIGH

Open-cluster-management-io/ocm: cluster-manager permissions may allow a worker node to obtain service account tokens

Published Dec 17, 2024

Description

A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which includes the permission to create Pod resources. If this deployment runs a pod on an attacker-controlled node, the attacker can obtain the cluster-manager's token and steal any service account token by creating and mounting the target service account to control the whole cluster.

Affected products

Remediation

Red Hat statement

This flaw affects upstream Open Cluster Management version 0.12.0 and was fixed in 0.13.0. No supported versions of Red Hat Advanced Cluster Management are affected.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 17, 2024
Updated Feb 25, 2026
Reserved Oct 10, 2024
CISA Vulnrichment
Updated Dec 18, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 30, 2023
GHSA-JHH6-6FHP-Q2XP