Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Advanced Cluster Management For Kubernetes
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25655 1 Redhat 1 Advanced Cluster Management For Kubernetes 2020-11-18 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.