CyberRota Analysis
AI-GeneratedA privilege escalation vulnerability exists in the Portworx Operator when deployed on Red Hat OpenShift, allowing users with limited, namespace-scoped permissions to gain broader access during the initial provisioning of a Portworx storage cluster. This could lead to unauthorized elevation of privileges within the Kubernetes environment, posing significant security risks. Organizations utilizing Kubernetes with Portworx on OpenShift should prioritize addressing this vulnerability to safeguard their cluster integrity.
Original NVD Description
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.