Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/open-feature/open-feature-operator: CVE-2023-29018 #1725

Closed
GoVulnBot opened this issue Apr 14, 2023 · 1 comment
Assignees

Comments

@GoVulnBot
Copy link

CVE-2023-29018 references github.com/open-feature/open-feature-operator, which may be a Go module.

Description:
The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on open-feature-operator-controller-manager to escalate the privileges of any SA in the cluster. The increased privileges could be used to modify cluster state, leading to DoS, or read sensitive data, including secrets. Version 0.2.32 mitigates this issue by restricting the resources the open-feature-operator-controller-manager can modify.

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/open-feature/open-feature-operator
    packages:
      - package: open-feature-operator
description: |
    The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on `open-feature-operator-controller-manager` to escalate the privileges of any SA in the cluster. The increased privileges could be used to modify cluster state, leading to DoS, or read sensitive data, including secrets. Version 0.2.32 mitigates this issue by restricting the resources the `open-feature-operator-controller-manager` can modify.
cves:
  - CVE-2023-29018
references:
  - advisory: https://github.com/open-feature/open-feature-operator/security/advisories/GHSA-cwf6-xj49-wp83
  - web: https://github.com/open-feature/open-feature-operator/releases/tag/v0.2.32

@timothy-king
Copy link
Contributor

Duplicate of #1721

@timothy-king timothy-king marked this as a duplicate of #1721 Apr 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants