Kuadrant Privilege Escalation Vulnerability via Service Account Token Access

Vulnerability

A vulnerability in Kuadrant version 0.11.3 allows attackers to access the service account's token due to insecure permissions. This access can lead to privilege escalation through the secrets component in the Kubernetes cluster, potentially allowing an attacker to take over the cluster.

Impact

Exploitation of this vulnerability could result in unauthorized access to the Kubernetes API, allowing an attacker to act as a legitimate user with the service account's privileges. This access could be used to retrieve all secrets in the cluster and exploit sensitive information to elevate privileges further, up to and including a complete takeover of the cluster.

Reproduction

To reproduce this vulnerability, a malicious user can exploit the insecure permissions to steal the service account token. For example, in a project called Hwameistor, a DaemonSet named 'hwameistor-local-disk-manager' runs with a cluster role that allows updating node resources. If a malicious user gains control of a worker node, the 'hwameistor-local-disk-manager' pod can be used to patch other nodes, potentially forcing the 'kuadrant-operator' pod onto the compromised worker node. Once the pod is running with elevated permissions, the token can be stolen.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.