CyberRota Analysis
AI-GeneratedA critical vulnerability exists in the multicloud-integrations component of Red Hat Advanced Cluster Management, allowing authenticated users (tenants) to manipulate the GitOpsCluster controller. This exploitation enables tenants to redirect sensitive bearer tokens from secure locations to their controlled namespaces, potentially leading to unauthorized access to critical information and the circumvention of security policies in ArgoCD AppProjects. Organizations using RHACM should prioritize immediate remediation efforts to mitigate the risk of data exposure and security breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.