CyberRota Analysis
AI-GeneratedA vulnerability exists in multicluster-global-hub that improperly grants all managed hubs read access to a shared communication topic during ManagedClusterMigration. This flaw allows a compromised managed hub to intercept sensitive bootstrap kubeconfigs, which include long-lived API server tokens for other hubs, posing a significant risk of unauthorized access and data exposure. Organizations utilizing multicluster-global-hub should prioritize addressing this issue to safeguard their cluster communications and sensitive configurations.
Original NVD Description
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.