CyberRota Analysis
AI-GeneratedA vulnerability exists in the managed-serviceaccount component, where a compromised addon-manager pod can exploit excessive permissions granted by its ClusterRole to access any secret across all namespaces and approve arbitrary Certificate Signing Requests (CSRs). This could lead to significant information disclosure and privilege escalation within the Kubernetes cluster. Organizations utilizing Kubernetes should prioritize addressing this issue to mitigate potential security breaches.
Original NVD Description
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.