piraeus-operator allows attacker to impersonate service account
        
  High severity
        
          GitHub Reviewed
      
        Published
          May 3, 2024 
          to the GitHub Advisory Database
          •
          Updated Jul 3, 2024 
      
  
Package
Affected versions
<= 2.5.0
  Patched versions
None
  Description
        Published by the National Vulnerability Database
      May 3, 2024 
    
  
        Published to the GitHub Advisory Database
      May 3, 2024 
    
  
        Reviewed
      May 3, 2024 
    
  
        Last updated
      Jul 3, 2024 
    
  
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.
References