CyberRota Analysis
AI-GeneratedA vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to create malicious EndpointSlices with attacker-controlled IP addresses. This can lead to redirection of legitimate service traffic, enabling remote attackers to perform transparent Man-in-the-Middle (MITM) attacks on cross-cluster communications, risking unauthorized data access and manipulation. Organizations using Kubernetes, particularly those leveraging Red Hat's Advanced Cluster Management, should prioritize addressing this high-severity issue to safeguard their environments.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.