CyberRota Analysis
AI-GeneratedElastic Cloud on Kubernetes (ECK) is vulnerable to incorrect authorization, allowing an attacker with limited permissions in one namespace to manipulate data through metadata spoofing. This could result in unauthorized modifications to the Elasticsearch client trust bundle in a different namespace, potentially compromising data integrity and security. Organizations using Kubernetes, particularly those deploying ECK, should prioritize addressing this vulnerability to safeguard their environments.
Original NVD Description
Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
Related CVEs
Other vulnerabilities affecting the same vendor(s)